awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Cloud Security Configuration Auditors

Ranking updated Jun 30, 2026

For a cloud security posture tool, the strongest matches are tenable/terrascan (Terrascan is a static analysis tool for infrastructure-as-code that), toniblyx/prowler (Prowler is a multi-cloud security scanner that automates assessments) and aquasecurity/trivy (Trivy is a comprehensive security scanner that detects misconfigurations). alfresco/prowler and prowler-cloud/prowler round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Automated tools that scan cloud infrastructure environments to identify and report potential security misconfigurations and vulnerabilities.

Cloud Security Configuration Auditors

Find the best repos with AI.We'll search the best matching repositories with AI.
  • tenable/terrascantenable avatar

    tenable/terrascan

    5,210View on GitHub↗

    Terrascan is a static analysis tool designed to evaluate infrastructure-as-code configuration files for security vulnerabilities and compliance violations. By parsing these files into an intermediate representation, it identifies risks before cloud resources are provisioned, serving as a compliance auditor for cloud-native environments. The tool functions as a policy-as-code engine, allowing users to define and enforce custom security rules and industry benchmarks using a specialized query language. It distinguishes itself through its ability to integrate directly into development and deploym

    Terrascan is a static analysis tool for infrastructure-as-code that scans Terraform, Kubernetes, and similar IaC files for security misconfigurations and compliance violations across AWS, GCP, and Azure, with policy-as-code and CIS benchmark support—exactly the kind of tool you need, though it focuses on pre-deployment IaC scanning rather than live cloud environments.

    GoInfrastructure Policy EnforcementPolicy-As-Code Engines
    View on GitHub↗5,210
  • toniblyx/prowlertoniblyx avatar

    toniblyx/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Prowler is a multi-cloud security scanner that automates assessments across AWS, GCP, and Azure, evaluating against CIS benchmarks and producing a dashboard with attack‑path visualizations — exactly the kind of actionable audit report this search is after.

    PythonAutomated Security Scan Triggers
    View on GitHub↗14,005
  • aquasecurity/trivyaquasecurity avatar

    aquasecurity/trivy

    36,462View on GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Trivy is a comprehensive security scanner that detects misconfigurations in infrastructure as code and cloud environments across AWS, GCP, and Azure, with automated scanning, CIS benchmark checks, policy-as-code via Rego, and built-in reporting and remediation guidance.

    GoContainer Security ScannersVulnerability ScannersInfrastructure as Code Scanners
    View on GitHub↗36,462
  • alfresco/prowlerAlfresco avatar

    Alfresco/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove

    Prowler is a dedicated multi-cloud security posture scanner that runs automated audits against AWS, GCP, and Azure, checks CIS benchmarks, and presents results in a dashboard — exactly the kind of tool this search targets.

    PythonCloud Security Posture ManagementAI Security Context ServersAI Security Data Providers
    View on GitHub↗14,005
  • prowler-cloud/prowlerprowler-cloud avatar

    prowler-cloud/prowler

    13,049View on GitHub↗

    Prowler is an automated cloud infrastructure security scanner and posture management tool. It evaluates cloud environments and infrastructure-as-code templates against security benchmarks to identify misconfigurations, vulnerabilities, and compliance gaps that could compromise system integrity. The platform distinguishes itself through graph-based attack path analysis, which identifies chains of misconfigurations that create exploitable routes for unauthorized access. It utilizes a plugin-based execution model to perform state-based assessments of live environments and static analysis of conf

    Prowler is an automated multi-cloud security scanner covering AWS, Azure, and GCP with built-in CIS benchmark checks, automated scanning, and graph-based attack path analysis—exactly what you need for misconfiguration detection and audit-ready reports.

    PythonCloud Auditing ToolsCloud Security ToolsInfrastructure Security Scanners
    View on GitHub↗13,049
  • nccgroup/scoutsuitenccgroup avatar

    nccgroup/ScoutSuite

    7,548View on GitHub↗

    ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul

    ScoutSuite is a multi-cloud security audit tool that directly maps to the search, scanning AWS, GCP, and Azure for misconfigurations and generating detailed HTML audit reports with compliance benchmarking, making it a flagship example of the category.

    PythonCloud Auditing ToolsCloud Compliance AuditorsAWS
    View on GitHub↗7,548
  • bridgecrewio/checkovbridgecrewio avatar

    bridgecrewio/checkov

    8,798View on GitHub↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Checkov is a leading open-source static analysis tool that scans infrastructure-as-code across AWS, GCP, and Azure for misconfigurations, supports CIS benchmarks, and provides automated scanning with actionable reports and policy-as-code features.

    PythonInfrastructure as Code ScannersInfrastructure as Code SecurityStatic Code Analysis
    View on GitHub↗8,798
  • cloudsploit/scanscloudsploit avatar

    cloudsploit/scans

    3,748View on GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    This is a dedicated open-source CSPM scanner that automatically checks AWS, GCP, and Azure for misconfigurations against CIS benchmarks, producing actionable reports — exactly the multi-cloud audit tool you're looking for.

    JavaScriptCloud Security Posture ManagementAutomated Security RemediationCloud Auditing Tools
    View on GitHub↗3,748
  • aquasecurity/tfsecaquasecurity avatar

    aquasecurity/tfsec

    7,013View on GitHub↗

    tfsec is a static analysis tool and infrastructure as code linter designed to detect security misconfigurations and compliance violations in Terraform infrastructure code. It functions as a cloud security posture tool and policy enforcement engine that evaluates configurations against established security benchmarks. The tool provides multi-cloud security auditing for providers including AWS, Azure, Google Cloud, and Kubernetes, as well as specialized scanning for DigitalOcean, OpenStack, CloudStack, and GitHub configurations. It identifies insecure settings such as public access or unencrypt

    tfsec is a static analysis tool that checks Terraform configuration files for security misconfigurations across AWS, Azure, GCP, and more, making it a cloud security scanner that focuses on infrastructure-as-code rather than live cloud environments.

    GoInfrastructure as Code SecurityStatic Analysis EnginesCloud Security Posture Scanners
    View on GitHub↗7,013
  • accurics/terrascanaccurics avatar

    accurics/terrascan

    5,210View on GitHub↗

    Terrascan is an infrastructure as code security scanner and cloud configuration auditor designed to detect security violations and compliance risks in cloud templates and Dockerfiles before provisioning. It utilizes the Open Policy Agent to evaluate infrastructure templates against both standard security policies and custom organizational rules. The project functions as a security guardrail within build pipelines, blocking risky deployments by integrating scanning logic directly into CI/CD workflows. It also includes a container registry vulnerability scanner that collects vulnerability data

    Terrascan is a policy-as-code security scanner that audits cloud infrastructure templates (including multi-cloud) for misconfigurations and compliance violations, and integrates into CI/CD pipelines for automated scanning and reporting—fitting your search for a cloud security misconfiguration scanner, though it focuses on pre-deployment templates rather than live cloud environments.

    GoInfrastructure as Code ScannersPolicy-Based ValidationsCI/CD Pipeline Integrations
    View on GitHub↗5,210
  • awslabs/automated-security-helperawslabs avatar

    awslabs/automated-security-helper

    598View on GitHub↗

    The automated security helper is a command-line utility designed to orchestrate multiple security analysis tools into a unified, configuration-driven workflow. It functions as a central engine that executes static application security testing and infrastructure scans, aggregating diverse tool outputs into a standardized, machine-readable format to ensure consistent vulnerability detection across development lifecycles. The tool distinguishes itself through a modular plugin architecture that allows for the integration of custom or proprietary scanners, alongside an external intelligence layer

    This repository is an AWS-focused security scanner that checks IaC templates for misconfigurations, fitting the "cloud security misconfiguration scanner" category but limited to AWS only and lacking multi-cloud support, CIS compliance, and a full reporting dashboard.

    PythonScanner OrchestratorsSecurity Vulnerability ScanningCLI Execution
    View on GitHub↗598
  • tfsec/tfsectfsec avatar

    tfsec/tfsec

    7,013View on GitHub↗

    tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect misconfigurations and compliance violations in Terraform and cloud infrastructure definitions before deployment. It functions as a cloud security policy engine that identifies vulnerabilities across multiple cloud platforms. The tool provides capabilities for cloud compliance auditing and scanning of Cloud Development Kit code. It supports custom security policy enforcement and allows for the definition of organization-specific security requirements. The scanner includes features

    tfsec is a static analysis security scanner for Terraform and cloud infrastructure code that detects misconfigurations across AWS, GCP, and Azure, with CIS benchmark compliance and custom policy support — it fits the search well if you are scanning infrastructure definitions before deployment, though it does not scan live cloud accounts.

    GoStatic Analysis EnginesStatic Configuration AnalysisCloud Compliance Auditors
    View on GitHub↗7,013
  • aquasecurity/cloudsploitaquasecurity avatar

    aquasecurity/cloudsploit

    3,705View on GitHub↗

    Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource

    Cloudsploit is a multi-cloud security auditor that scans AWS, Azure, GCP, and others for misconfigurations, maps results to compliance frameworks, and offers automated remediation, fitting your need for an open-source cloud security misconfiguration scanner with actionable reports.

    JavaScriptCloud Compliance AuditorsCloud Infrastructure SecurityAutomated Configuration Remediation
    View on GitHub↗3,705

Related searches

  • an automated security auditing tool for AWS
  • a cloud resource inventory tool
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
tenable/terrascan5.2KGoApache-2.0Nov 20, 2025
toniblyx/prowler14KPythonApache-2.0Jun 17, 2026
aquasecurity/trivy36.5KGoApache-2.0Jun 16, 2026
alfresco/prowler14KPythonApache-2.0Jun 17, 2026
prowler-cloud/prowler13KPythonapache-2.0Feb 19, 2026
nccgroup/scoutsuite7.5KPythongpl-2.0Sep 23, 2025
bridgecrewio/checkov8.8KPythonApache-2.0Jun 15, 2026
cloudsploit/scans3.7KJavaScriptGPL-3.0Feb 23, 2026
aquasecurity/tfsec7KGoMITMar 25, 2026
accurics/terrascan5.2KGoApache-2.0Nov 20, 2025
an IaC security scanner
  • a tool for cleaning up idle cloud resources
  • a Kubernetes config auditing tool
  • a cloud cost monitoring tool
  • a tool for querying cloud resources with SQL
  • an asset discovery and exposure tool