awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to nccgroup/pmapper

Open-source alternatives to PMapper

30 open-source projects similar to nccgroup/pmapper, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best PMapper alternative.

  • nccgroup/scoutsuitenccgroup avatar

    nccgroup/ScoutSuite

    7,548View on GitHub↗

    ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul

    Pythonauditingawsazure
    View on GitHub↗7,548
  • toniblyx/prowlertoniblyx avatar

    toniblyx/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    View on GitHub↗14,005
  • cloudsploit/scanscloudsploit avatar

    cloudsploit/scans

    3,748View on GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    JavaScript
    View on GitHub↗3,748

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • cisagov/sparrowcisagov avatar

    cisagov/Sparrow

    1,430View on GitHub↗

    Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.

    PowerShell
    View on GitHub↗1,430
  • nccgroup/aws-inventorynccgroup avatar

    nccgroup/aws-inventory

    740View on GitHub↗

    Discover resources created in an AWS account.

    Python
    View on GitHub↗740
  • awslabs/aws-security-benchmarkawslabs avatar

    awslabs/aws-security-benchmark

    620View on GitHub↗

    Open source demos, concept and guidance related to the AWS CIS Foundation framework.

    Python
    View on GitHub↗620
  • duo-labs/cloudmapperduo-labs avatar

    duo-labs/cloudmapper

    6,259View on GitHub↗
    JavaScriptawscytoscapediagram
    View on GitHub↗6,259
  • cyberark/skyarkcyberark avatar

    cyberark/SkyArk

    912View on GitHub↗

    SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

    PowerShell
    View on GitHub↗912
  • rams3sh/aaiarams3sh avatar

    rams3sh/Aaia

    297View on GitHub↗

    AWS Identity and Access Management Visualizer and Anomaly Finder

    Python
    View on GitHub↗297
  • salesforce/cloudsplainingsalesforce avatar

    salesforce/cloudsplaining

    2,226View on GitHub↗

    Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

    JavaScript
    View on GitHub↗2,226
  • duo-labs/cloudtrackerduo-labs avatar

    duo-labs/cloudtracker

    911View on GitHub↗

    CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies.

    Python
    View on GitHub↗911
  • securityftw/cs-suiteSecurityFTW avatar

    SecurityFTW/cs-suite

    1,172View on GitHub↗

    Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

    Shellaws-auditaws-securityazure
    View on GitHub↗1,172
  • darkbitio/aws-recondarkbitio avatar

    darkbitio/aws-recon

    557View on GitHub↗

    Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

    Ruby
    View on GitHub↗557
  • cyberark/skywrappercyberark avatar

    cyberark/SkyWrapper

    107View on GitHub↗

    SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

    Python
    View on GitHub↗107
  • aws-cloudformation/cloudformation-guardaws-cloudformation avatar

    aws-cloudformation/cloudformation-guard

    1,384View on GitHub↗

    Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

    Rust
    View on GitHub↗1,384
  • aquasecurity/kube-hunteraquasecurity avatar

    aquasecurity/kube-hunter

    5,064View on GitHub↗

    Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native penetration tool designed to identify security weaknesses, infrastructure misconfigurations, and exploitable gaps by simulating attacker techniques. The tool distinguishes itself through a dual-mode scanning engine that executes both remote external probes and internal network scans. It features identity-based impersonation, allowing it to use service account tokens and pod identities to simulate security access from specific cluster roles and determine the potential blast radius

    Python
    View on GitHub↗5,064
  • anaynayak/aws-security-vizanaynayak avatar

    anaynayak/aws-security-viz

    721View on GitHub↗

    Visualize your aws security groups.

    Ruby
    View on GitHub↗721
  • aquasecurity/kube-benchaquasecurity avatar

    aquasecurity/kube-bench

    8,078View on GitHub↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    Go
    View on GitHub↗8,078
  • anssi-fr/dfir-o365rcA

    ANSSI-FR/DFIR-O365RC

    0View on GitHub↗
    View on GitHub↗0
  • aliyun/oss-browseraliyun avatar

    aliyun/oss-browser

    3,585View on GitHub↗

    OSS Browser 提供类似windows资源管理器功能。用户可以很方便的浏览文件,上传下载文件,支持断点续传等。

    JavaScript
    View on GitHub↗3,585
  • aletheia/iam-policy-generatoraletheia avatar

    aletheia/iam-policy-generator

    154View on GitHub↗

    A simple library to generate IAM policy statements with no need to remember all the actions APIs

    TypeScript
    View on GitHub↗154
  • bridgecrewio/airiambridgecrewio avatar

    bridgecrewio/AirIAM

    824View on GitHub↗

    Least privilege AWS IAM Terraformer

    Python
    View on GitHub↗824
  • bridgecrewio/cdkgoatbridgecrewio avatar

    bridgecrewio/cdkgoat

    48View on GitHub↗

    CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    Python
    View on GitHub↗48
  • bridgecrewio/cfngoatbridgecrewio avatar

    bridgecrewio/cfngoat

    97View on GitHub↗

    Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    View on GitHub↗97
  • carlospolop/purplepandaC

    carlospolop/PurplePanda

    0View on GitHub↗
    View on GitHub↗0
  • carnal0wnage/weirdaalcarnal0wnage avatar

    carnal0wnage/weirdAAL

    844View on GitHub↗

    WeirdAAL (AWS Attack Library)

    Python
    View on GitHub↗844
  • cdk-team/cdkcdk-team avatar

    cdk-team/CDK

    4,692View on GitHub↗

    CDK is a specialized toolset for container security auditing, container escape exploitation, and cloud infrastructure pentesting. It provides a collection of scripts and tools designed to identify and exploit vulnerabilities in container runtimes to break out of isolated environments and execute commands on the underlying host operating system. The project features a dedicated Docker runtime exploit suite for abusing the Docker API, procfs, and cgroups to gain unauthorized host-level access. It includes specific techniques for bypassing isolation via LXCFS, user namespace exploitation, and ho

    Go
    View on GitHub↗4,692
  • chaitin/veinmind-toolschaitin avatar

    chaitin/veinmind-tools

    1,649View on GitHub↗

    问脉已接入 openai, 可以使用 openai 对扫描的结果进行人性化分析,让您更加清晰的了解本次扫描发现了哪些风险。

    Go
    View on GitHub↗1,649
  • bloodhoundad/azurehoundB

    BloodHoundAD/AzureHound

    0View on GitHub↗
    View on GitHub↗0
  • anssi-fr/adtimelineANSSI-FR avatar

    ANSSI-FR/ADTimeline

    525View on GitHub↗

    1. The ADTimeline PowerShell script 1. Description 2. Prerequisites 3. Usage 4. Files generated 5. Custom groups 2. The ADTimeline App for Splunk 1. Description 2. Sourcetypes 3. AD General information dashboards 4. AD threat hunting dashboards 5. Enhance your traditional event logs threat…

    PowerShell
    View on GitHub↗525