awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

14 个仓库

Awesome GitHub RepositoriesCloud Security Auditing

Tools for enumerating and auditing cloud infrastructure and storage buckets.

Explore 14 awesome GitHub repositories matching part of an awesome list · Cloud Security Auditing. Refine with filters or upvote what's useful.

Awesome Cloud Security Auditing GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • aquasecurity/trivyaquasecurity 的头像

    aquasecurity/trivy

    36,462在 GitHub 上查看↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Comprehensive security scanner for cloud-native environments.

    Gocontainersdevsecopsdocker
    在 GitHub 上查看↗36,462
  • toniblyx/prowlertoniblyx 的头像

    toniblyx/prowler

    14,005在 GitHub 上查看↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Security tool for cloud best practices, compliance, and forensics.

    Python
    在 GitHub 上查看↗14,005
  • nccgroup/scoutsuitenccgroup 的头像

    nccgroup/ScoutSuite

    7,548在 GitHub 上查看↗

    ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul

    Multi-cloud security auditing tool for assessing environment posture.

    Pythonauditingawsazure
    在 GitHub 上查看↗7,548
  • streaak/keyhacksstreaak 的头像

    streaak/keyhacks

    6,069在 GitHub 上查看↗

    Keyhacks is a command-line tool that tests whether API keys and tokens for dozens of cloud services are valid and active. It automates the verification of discovered credentials during security auditing and penetration testing, confirming if leaked or harvested API keys, tokens, and secrets are still operational. The tool validates credentials by sending lightweight, service-specific HTTP requests to each platform's API endpoint and inspecting the response status or body. Each validation runs independently without storing state between requests, using pre-defined request templates with the co

    Validates API keys found during bug bounty engagements.

    在 GitHub 上查看↗6,069
  • rhinosecuritylabs/pacuRhinoSecurityLabs 的头像

    RhinoSecurityLabs/pacu

    5,234在 GitHub 上查看↗

    Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments. It serves as a cloud penetration testing tool and resource enumerator used to identify misconfigurations, map attack surfaces, and execute privilege escalation paths. The framework provides specialized capabilities for post-exploitation and red team operations, including establishing persistence through identity and access management backdooring. It distinguishes itself with a plugin-based module system that allows for the development of custom tasks and the orchestration of A

    Offensive security framework for testing AWS environments.

    Python
    在 GitHub 上查看↗5,234
  • cloudflare/flancloudflare 的头像

    cloudflare/flan

    4,162在 GitHub 上查看↗

    Flan 是一款容器化网络漏洞扫描器和安全审计员。它识别网络上的开放端口和服务版本,以检测已知的安全弱点和配置错误。 该系统旨在在隔离的容器环境中运行,利用配置映射来管理目标列表和密钥。它包括一个用于将扫描输出文件和安全分析数据归档到远程 S3 存储桶以进行长期存储的专用机制。 该工具生成格式化的漏洞摘要和安全报告,以供技术分析使用。它支持将原始扫描数据导出到远程云存储,以进行集中式安全审计。

    Enables centralized security analysis by archiving network scan data to cloud storage.

    Python
    在 GitHub 上查看↗4,162
  • cloudsploit/scanscloudsploit 的头像

    cloudsploit/scans

    3,748在 GitHub 上查看↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    Detects security risks in cloud infrastructure accounts.

    JavaScript
    在 GitHub 上查看↗3,748
  • salesforce/cloudsplainingsalesforce 的头像

    salesforce/cloudsplaining

    2,226在 GitHub 上查看↗

    Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

    Assesses AWS IAM policies for least privilege violations.

    JavaScript
    在 GitHub 上查看↗2,226
  • eth0izzle/bucket-streameth0izzle 的头像

    eth0izzle/bucket-stream

    1,809在 GitHub 上查看↗

    Find interesting Amazon S3 Buckets by watching certificate transparency logs.

    Finds public S3 buckets by monitoring certificate transparency logs.

    Python
    在 GitHub 上查看↗1,809
  • andresriancho/enumerate-iamandresriancho 的头像

    andresriancho/enumerate-iam

    1,242在 GitHub 上查看↗

    Enumerate the permissions associated with AWS credential set

    Enumerates permissions for discovered AWS credentials.

    Python
    在 GitHub 上查看↗1,242
  • ozguralp/gmapsapiscannerozguralp 的头像

    ozguralp/gmapsapiscanner

    1,178在 GitHub 上查看↗

    Used for determining whether a leaked/found Google Maps API Key is vulnerable to unauthorized access by other applications or not.

    Checks Google Maps API keys for unauthorized access vulnerabilities.

    Python
    在 GitHub 上查看↗1,178
  • virtuesecurity/aws-extenderVirtueSecurity 的头像

    VirtueSecurity/aws-extender

    258在 GitHub 上查看↗

    AWS Extender (Cloud Storage Tester) is a Burp plugin to assess permissions of cloud storage containers on AWS, Google Cloud and Azure.

    Burp Suite extension for identifying and testing cloud storage misconfigurations.

    Python
    在 GitHub 上查看↗258
  • netspi/gcpwnN

    NetSPI/gcpwn

    0在 GitHub 上查看↗

    Pentesting framework for enumerating and exploiting GCP environments.

    在 GitHub 上查看↗0
  • praetorian-inc/aurelianP

    praetorian-inc/aurelian

    0在 GitHub 上查看↗

    Unified framework for multi-cloud security reconnaissance.

    在 GitHub 上查看↗0
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Cloud Security Auditing