How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast
ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul
This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr
Open source demos, concept and guidance related to the AWS CIS Foundation framework.
A tool for quickly evaluating IAM permissions in AWS.
The main features of nccgroup/pmapper are: Cloud Platform Security, Cloud Security, Security Assessment Tools.
Open-source alternatives to nccgroup/pmapper include: toniblyx/prowler — Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance… nccgroup/scoutsuite — ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and… cyberark/skywrapper — SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS. cisagov/sparrow — Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications… cyberark/skyark — SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS. awslabs/aws-security-benchmark — Open source demos, concept and guidance related to the AWS CIS Foundation framework.