awesome-repositories.com
博客
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Netflix avatar

Netflix/security_monkeyArchived

0
View on GitHub↗
4,370 星标·781 分支·Python·Apache-2.0·2 次浏览

Security Monkey

Security Monkey 是一个云安全态势管理工具和配置审计器。它作为一个监控平台,跟踪云资产并记录状态变更,以识别安全策略何时被篡改或引入了不安全的配置。

该系统维护多云资产清单,跟踪 AWS、GCP、OpenStack 和 GitHub 组织中的资源。它提供了一个集中式界面,用于搜索和浏览跨多个云服务商和区域的资产。

该平台通过比较资源的历史状态来检测配置漂移,从而涵盖云安全审计和基础设施变更跟踪。它利用基于服务商的发现和统一资源索引来持续监控资产和策略。

Features

  • Cloud Security Monitoring - Audits and monitors cloud infrastructure configurations and permissions to detect insecure settings over time.
  • Cloud Asset Discoverers - Queries cloud provider APIs to identify, list, and track infrastructure resources across multiple environments.
  • State Snapshots - Detects configuration drift by comparing current resource states against stored historical snapshots.
  • Cloud Asset Inventory Managers - Maintains a global inventory of assets by consolidating resource lists from AWS, GCP, OpenStack, and GitHub.
  • Infrastructure Change Tracking - Records and compares historical states of cloud resources to identify precisely how configurations were modified.
  • Cloud Resource Inventory - Catalogs and tracks deployed cloud infrastructure components across multiple providers in a centralized inventory.
  • Unified Resource Models - Normalizes disparate data formats from multiple cloud providers into a consistent model for cross-platform security auditing.
  • Cloud Infrastructure Security Auditors - Analyzes multi-cloud resource configurations against security rules to identify when policies are altered.
  • Cloud Security Posture Management - Tracks and visualizes the security state of cloud accounts to detect insecure configurations and prioritize risk.
  • Cloud Asset Discovery Plugins - Utilizes provider-specific connector plugins to discover assets and fetch configurations from cloud and version control APIs.
  • Administrative Change Auditing - Maintains a verifiable history of administrative configuration changes to track when security policies were altered.
  • Configuration Delta Monitoring - Monitors assets and policy changes over time to detect insecure configurations and compliance drift.
  • Cloud Resource Search - Provides a unified interface to search and browse cloud resources across different providers, regions, and accounts.
  • Detector-Based Plugin Architectures - Implements a modular architecture where individual security vulnerability checks are developed as independent detector plugins.
  • Resource Change Monitors - Schedules periodic scans to monitor and alert on configuration changes and resource drift across cloud accounts.
  • Infrastructure Services - Monitors cloud infrastructure for security and configuration changes.
  • Systems And Services - Listed in the “Systems And Services” section of the The Book Of Secret Knowledge awesome list.

Star 历史

netflix/security_monkey 的 Star 历史图表netflix/security_monkey 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Security Monkey 的开源替代方案

相似的开源项目,按与 Security Monkey 的功能重合度排序。
  • projectdiscovery/subfinderprojectdiscovery 的头像

    projectdiscovery/subfinder

    13,105在 GitHub 上查看↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Gobugbountyhackinghacktoberfest
    在 GitHub 上查看↗13,105
  • mlabouardy/komisermlabouardy 的头像

    mlabouardy/komiser

    4,133在 GitHub 上查看↗

    Komiser is a multi-cloud infrastructure inspector and asset inventory manager. It provides a centralized system for auditing, cataloging, and analyzing deployed services and assets across AWS, GCP, and Azure environments. The project transforms disparate resource schemas from different cloud vendors into a unified structural representation through a provider-based plugin architecture. It uses agentless API inspection and polling-based resource discovery to retrieve metadata and configuration states without requiring agents on target resources. The platform covers financial management via cos

    Go
    在 GitHub 上查看↗4,133
  • projectdiscovery/naabuprojectdiscovery 的头像

    projectdiscovery/naabu

    5,766在 GitHub 上查看↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    在 GitHub 上查看↗5,766
  • cloudquery/cloudquerycloudquery 的头像

    cloudquery/cloudquery

    6,438在 GitHub 上查看↗

    CloudQuery is a cloud infrastructure ETL tool and multi-cloud data pipeline designed to collect, synchronize, and normalize resource metadata from various cloud providers and SaaS platforms. It functions as a centralized asset inventory manager and security posture manager, extracting configuration and state data into relational databases, data lakes, or data warehouses. The system distinguishes itself by transforming complex, nested cloud API responses into flat relational tables, enabling the use of standard SQL for asset querying and analysis. It employs a modular plugin system for data ex

    Goairbyteattack-surface-managementaws
    在 GitHub 上查看↗6,438
查看 Security Monkey 的所有 30 个替代方案→

常见问题解答

netflix/security_monkey 是做什么的?

Security Monkey 是一个云安全态势管理工具和配置审计器。它作为一个监控平台,跟踪云资产并记录状态变更,以识别安全策略何时被篡改或引入了不安全的配置。

netflix/security_monkey 的主要功能有哪些?

netflix/security_monkey 的主要功能包括:Cloud Security Monitoring, Cloud Asset Discoverers, State Snapshots, Cloud Asset Inventory Managers, Infrastructure Change Tracking, Cloud Resource Inventory, Unified Resource Models, Cloud Infrastructure Security Auditors。

netflix/security_monkey 有哪些开源替代品?

netflix/security_monkey 的开源替代品包括: projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… mlabouardy/komiser — Komiser is a multi-cloud infrastructure inspector and asset inventory manager. It provides a centralized system for… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… cloudsploit/scans — This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and… cloudquery/cloudquery — CloudQuery is a cloud infrastructure ETL tool and multi-cloud data pipeline designed to collect, synchronize, and… alfresco/prowler — Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for…