awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
nccgroup avatar

nccgroup/ScoutSuite

0
View on GitHub↗
7,548 stars·1,185 forks·Python·gpl-2.0·31 views

ScoutSuite

ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks.

The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rule testing without repeated API calls.

The system employs a JSON-based rule engine that supports custom security rule definitions, parameterized checks, and the suppression of specific findings. It manages authentication through credential files, managed identities, and temporary role assumptions, while generating visual security posture assessments via HTML reports and JSON exports.

The tool can be executed within a pre-configured container environment containing all necessary dependencies.

Features

  • Cloud Auditing Tools - Provides a multi-cloud auditing tool to assess infrastructure configurations against security best practices.
  • Cloud Compliance Auditors - Automates the evaluation of cloud infrastructure against industry-standard regulatory frameworks and security benchmarks.
  • Configuration Logic Evaluators - Evaluates resource configurations using nested logical operators and dynamic macros to detect security risks.
  • Offline Configuration Analysis - Evaluates cloud resource settings offline using cached data to test security rules without repeated API calls.
  • Control Plane Auditing - Scans Kubernetes control planes and master nodes across cloud providers to identify posture risks.
  • GCP Configuration Audits - Analyzes Google Cloud configurations across organizations and projects to identify security risks.
  • Cloud Provider Abstraction Layers - Employs unified interfaces to standardize the fetching of configuration data across multiple cloud service providers.
  • Cloud Security Posture Management - Gathers cloud configuration data to track and visualize the security posture of cloud accounts.
  • JSON-Based Rule Engines - Uses a JSON-based rule engine to evaluate cloud resource configurations against security benchmarks.
  • DigitalOcean Configuration Audits - Gathers configuration data from DigitalOcean APIs to perform security posture assessments.
  • AWS - Gathers security posture data from AWS APIs to identify risk areas.
  • Kubernetes Posture Scanning - Scans Kubernetes clusters and control planes across multiple cloud providers to identify security risks.
  • Security Rule Development - Allows the creation of tailored security checks to identify environment-specific risks.
  • HTML Analysis Reports - Generates structured HTML reports for visual inspection of cloud security posture and analysis results.
  • Local State Caches - Persists downloaded cloud configurations locally to allow iterative rule testing without repeating API calls.
  • Rule Parameterization - Supports using arguments within rule definitions to reuse a single security check across different values.
  • Cloud Provider Integrations - Enables the implementation of custom authentication strategies and data facades to integrate additional cloud platforms.
  • Multi-Account Scanning - Allows scanning a specific list of cloud subscriptions or all accessible accounts in one run.
  • Cloud Credential Management - Supports authenticating to cloud APIs using environment variables or credential files.
  • Custom Compliance Rulesets - Executes specific security findings based on industry-standard benchmarks using custom rulesets.
  • Temporary Security Tokens - Manages temporary security token exchanges and role assumptions to access multiple cloud accounts.
  • Identity Authentication - Provides support for connecting to cloud environments via CLI sessions, managed identities, and browser-based MFA.
  • AWS Role Assumption - Allows requesting temporary security credentials using role identifiers to perform audits in specific security contexts.
  • Security Finding Management - Allows marking specific resources as exceptions to security rules to suppress them from reports.
  • Security Report Generation - Generates security scan findings as structured HTML reports and JSON exports for stakeholders.
  • Offline Configuration Analysis - Performs security audits against downloaded configuration data to test rule changes without live API calls.
  • Collection and Analysis Decoupling - Implements a decoupled architecture that separates cloud data collection from security analysis to enable offline auditing.
  • Rule Evaluators - Allows passing external arguments and resolving resource IDs at runtime for flexible rule evaluation across environments.
  • Cloud Platform Security - Multi-cloud security auditing for posture assessment.
  • Cloud Security - Multi-cloud security scanning tool.
  • Cloud Security Tooling and Automation - Multi-cloud infrastructure security auditing tool.
  • Cloud Infrastructure Security - Multi-cloud security auditing tool for infrastructure assessment.
  • Cloud Security - Multi-cloud security auditing tool for configuration assessment.
  • Cloud Security Auditing - Multi-cloud security auditing tool for assessing environment posture.
  • Security Assessment Tools - Multi-cloud security auditing tool for infrastructure assessment.

Star history

Star history chart for nccgroup/scoutsuiteStar history chart for nccgroup/scoutsuite

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with ScoutSuite

These projects share indexed features with ScoutSuite. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • toniblyx/prowlertoniblyx avatar

    toniblyx/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    View on GitHub↗14,005
  • aquasecurity/cloudsploitaquasecurity avatar

    aquasecurity/cloudsploit

    3,705View on GitHub↗

    Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource

    JavaScriptalibabaaquaaws
    View on GitHub↗3,705
  • cloudsploit/scanscloudsploit avatar

    cloudsploit/scans

    3,748View on GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    JavaScript
    View on GitHub↗3,748
  • rhinosecuritylabs/pacuRhinoSecurityLabs avatar

    RhinoSecurityLabs/pacu

    5,234View on GitHub↗

    Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments. It serves as a cloud penetration testing tool and resource enumerator used to identify misconfigurations, map attack surfaces, and execute privilege escalation paths. The framework provides specialized capabilities for post-exploitation and red team operations, including establishing persistence through identity and access management backdooring. It distinguishes itself with a plugin-based module system that allows for the development of custom tasks and the orchestration of A

    Python
    View on GitHub↗5,234
Compare all 30 related projects→

Frequently asked questions

What does nccgroup/scoutsuite do?

ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks.

What are the main features of nccgroup/scoutsuite?

The main features of nccgroup/scoutsuite are: Cloud Auditing Tools, Cloud Compliance Auditors, Configuration Logic Evaluators, Offline Configuration Analysis, Control Plane Auditing, GCP Configuration Audits, Cloud Provider Abstraction Layers, Cloud Security Posture Management.

Which projects share features with nccgroup/scoutsuite?

Projects with overlapping indexed features include: toniblyx/prowler — Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance… aquasecurity/cloudsploit — Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud… cloudsploit/scans — This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and… rhinosecuritylabs/pacu — Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments.… aquasecurity/tfsec — tfsec is a static analysis tool and infrastructure as code linter designed to detect security misconfigurations and… 99designs/aws-vault — aws-vault is a secure credential manager and command-line wrapper for AWS. It stores long-term identity keys using the…