For a cloud security posture tool, the strongest matches are tenable/terrascan (Terrascan is a static analysis tool for infrastructure-as-code that), toniblyx/prowler (Prowler is a multi-cloud security scanner that automates assessments) and aquasecurity/trivy (Trivy is a comprehensive security scanner that detects misconfigurations). alfresco/prowler and prowler-cloud/prowler round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Automated tools that scan cloud infrastructure environments to identify and report potential security misconfigurations and vulnerabilities.
Terrascan is a static analysis tool designed to evaluate infrastructure-as-code configuration files for security vulnerabilities and compliance violations. By parsing these files into an intermediate representation, it identifies risks before cloud resources are provisioned, serving as a compliance auditor for cloud-native environments. The tool functions as a policy-as-code engine, allowing users to define and enforce custom security rules and industry benchmarks using a specialized query language. It distinguishes itself through its ability to integrate directly into development and deploym
Terrascan is a static analysis tool for infrastructure-as-code that scans Terraform, Kubernetes, and similar IaC files for security misconfigurations and compliance violations across AWS, GCP, and Azure, with policy-as-code and CIS benchmark support—exactly the kind of tool you need, though it focuses on pre-deployment IaC scanning rather than live cloud environments.
Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast
Prowler is a multi-cloud security scanner that automates assessments across AWS, GCP, and Azure, evaluating against CIS benchmarks and producing a dashboard with attack‑path visualizations — exactly the kind of actionable audit report this search is after.
Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai
Trivy is a comprehensive security scanner that detects misconfigurations in infrastructure as code and cloud environments across AWS, GCP, and Azure, with automated scanning, CIS benchmark checks, policy-as-code via Rego, and built-in reporting and remediation guidance.
Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove
Prowler is a dedicated multi-cloud security posture scanner that runs automated audits against AWS, GCP, and Azure, checks CIS benchmarks, and presents results in a dashboard — exactly the kind of tool this search targets.
Prowler is an automated cloud infrastructure security scanner and posture management tool. It evaluates cloud environments and infrastructure-as-code templates against security benchmarks to identify misconfigurations, vulnerabilities, and compliance gaps that could compromise system integrity. The platform distinguishes itself through graph-based attack path analysis, which identifies chains of misconfigurations that create exploitable routes for unauthorized access. It utilizes a plugin-based execution model to perform state-based assessments of live environments and static analysis of conf
Prowler is an automated multi-cloud security scanner covering AWS, Azure, and GCP with built-in CIS benchmark checks, automated scanning, and graph-based attack path analysis—exactly what you need for misconfiguration detection and audit-ready reports.
ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul
ScoutSuite is a multi-cloud security audit tool that directly maps to the search, scanning AWS, GCP, and Azure for misconfigurations and generating detailed HTML audit reports with compliance benchmarking, making it a flagship example of the category.
Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security
Checkov is a leading open-source static analysis tool that scans infrastructure-as-code across AWS, GCP, and Azure for misconfigurations, supports CIS benchmarks, and provides automated scanning with actionable reports and policy-as-code features.
This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr
This is a dedicated open-source CSPM scanner that automatically checks AWS, GCP, and Azure for misconfigurations against CIS benchmarks, producing actionable reports — exactly the multi-cloud audit tool you're looking for.
tfsec is a static analysis tool and infrastructure as code linter designed to detect security misconfigurations and compliance violations in Terraform infrastructure code. It functions as a cloud security posture tool and policy enforcement engine that evaluates configurations against established security benchmarks. The tool provides multi-cloud security auditing for providers including AWS, Azure, Google Cloud, and Kubernetes, as well as specialized scanning for DigitalOcean, OpenStack, CloudStack, and GitHub configurations. It identifies insecure settings such as public access or unencrypt
tfsec is a static analysis tool that checks Terraform configuration files for security misconfigurations across AWS, Azure, GCP, and more, making it a cloud security scanner that focuses on infrastructure-as-code rather than live cloud environments.
Terrascan is an infrastructure as code security scanner and cloud configuration auditor designed to detect security violations and compliance risks in cloud templates and Dockerfiles before provisioning. It utilizes the Open Policy Agent to evaluate infrastructure templates against both standard security policies and custom organizational rules. The project functions as a security guardrail within build pipelines, blocking risky deployments by integrating scanning logic directly into CI/CD workflows. It also includes a container registry vulnerability scanner that collects vulnerability data
Terrascan is a policy-as-code security scanner that audits cloud infrastructure templates (including multi-cloud) for misconfigurations and compliance violations, and integrates into CI/CD pipelines for automated scanning and reporting—fitting your search for a cloud security misconfiguration scanner, though it focuses on pre-deployment templates rather than live cloud environments.
The automated security helper is a command-line utility designed to orchestrate multiple security analysis tools into a unified, configuration-driven workflow. It functions as a central engine that executes static application security testing and infrastructure scans, aggregating diverse tool outputs into a standardized, machine-readable format to ensure consistent vulnerability detection across development lifecycles. The tool distinguishes itself through a modular plugin architecture that allows for the integration of custom or proprietary scanners, alongside an external intelligence layer
This repository is an AWS-focused security scanner that checks IaC templates for misconfigurations, fitting the "cloud security misconfiguration scanner" category but limited to AWS only and lacking multi-cloud support, CIS compliance, and a full reporting dashboard.
tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect misconfigurations and compliance violations in Terraform and cloud infrastructure definitions before deployment. It functions as a cloud security policy engine that identifies vulnerabilities across multiple cloud platforms. The tool provides capabilities for cloud compliance auditing and scanning of Cloud Development Kit code. It supports custom security policy enforcement and allows for the definition of organization-specific security requirements. The scanner includes features
tfsec is a static analysis security scanner for Terraform and cloud infrastructure code that detects misconfigurations across AWS, GCP, and Azure, with CIS benchmark compliance and custom policy support — it fits the search well if you are scanning infrastructure definitions before deployment, though it does not scan live cloud accounts.
Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource
Cloudsploit is a multi-cloud security auditor that scans AWS, Azure, GCP, and others for misconfigurations, maps results to compliance frameworks, and offers automated remediation, fitting your need for an open-source cloud security misconfiguration scanner with actionable reports.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| tenable/terrascan | 5.2K | Go | Apache-2.0 | |
| toniblyx/prowler | 14K | Python | Apache-2.0 | |
| aquasecurity/trivy | 36.5K | Go | Apache-2.0 | |
| alfresco/prowler | 14K | Python | Apache-2.0 | |
| prowler-cloud/prowler | 13K | Python | apache-2.0 | |
| nccgroup/scoutsuite | 7.5K | Python | gpl-2.0 | |
| bridgecrewio/checkov | 8.8K | Python | Apache-2.0 | |
| cloudsploit/scans | 3.7K | JavaScript | GPL-3.0 | |
| aquasecurity/tfsec | 7K | Go | MIT | |
| accurics/terrascan | 5.2K | Go | Apache-2.0 |