cloudmapper
prowler
Our great sponsors
cloudmapper | prowler | |
---|---|---|
8 | 24 | |
5,830 | 9,514 | |
0.9% | 3.0% | |
3.6 | 9.9 | |
22 days ago | 7 days ago | |
JavaScript | Python | |
BSD 3-clause "New" or "Revised" License | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
cloudmapper
-
A humble idea to fetch the AWS cloud resources to make them inventoriable as possible. Make it easy to query for resources and help on a daily basis work [devops].
cloudmapper
- Diagram Aws account
- Tool to map out resources!
-
Is there a good tool to “map” out AWS infrastructure in your account?
if u want an open source alternative try this: https://github.com/duo-labs/cloudmapper
- Is there a tool to map a AWS/vpc environment?
-
Is there any way to efficiently audit security groups?
You can use CloudMapper for some visualizations and CMDB but the diagram is kinda difficult and you have to put some effort into it.
-
How to map all resources in an account I don't know
You could try https://github.com/duo-labs/cloudmapper
-
A magic button to capture AWS infra state?
CloudMapper helps you analyze your Amazon Web Services (AWS) environments. The original purpose was to generate network diagrams and display them in your browser. It now contains much more functionality, including auditing for security issues.
prowler
-
Ask HN: Cloud security auditing for indie-grade projects?
Which cloud provider?
https://github.com/prowler-cloud/prowler is easy to get going with, and gives decent results. It's much stronger at AWS than GCP or Azure.
Steampipe can be a little harder to wrap your head around, but scales really well and has broader support: https://hub.steampipe.io/mods?objectives=security
-
Automating AWS Prowler Scans
Task Role: Select or create a new role that has the necessary permissions. Ensure this role has the three required Prowler policies and an additional custom policy to put objects into the desired S3 bucket.
-
Azure and M365 Secure Config Review
Prowler and ScoutSuite are a good start for cloud stuff.
- AWS Account - Analysis
-
Open source alternative cloud security tool that works like Wiz/Lacework/Aqua
Yes! There are open source cloud security tools! Here are some open source tools out there: steampipe, prowler, cloudquery, and ZeusCloud.
-
CSPM opensource suggestions
If AWS is in use then i would add prowler to the list - https://github.com/prowler-cloud/prowler This is the best open source cspm for aws.
-
Practical way for security assestment in AWS with Prowler
More info you can find it at Prowler Github and Prowler Docs
- AWS Security Scanner
-
Opensource equivalent of Sailpoint
You’re not going to find a shiny enterprise web ui for free but there are tools out there. If you just want to review AWS accounts, you can use prowler https://github.com/prowler-cloud/prowler
-
Automated penetration testing for a cloud infrastructure
Here is a good open source option to get started: https://github.com/prowler-cloud/prowler
What are some alternatives?
ScoutSuite - Multi-Cloud Security Auditing Tool
workload-discovery-on-aws - Workload Discovery on AWS is a solution to visualize AWS Cloud workloads. With it you can build, customize, and share architecture diagrams of your workloads based on live data from AWS. The solution maintains an inventory of the AWS resources across your accounts and regions, mapping their relationships and displaying them in the user interface.
steampipe-mod-aws-compliance - Run individual controls or full compliance benchmarks for CIS, PCI, NIST, HIPAA and more across all of your AWS accounts using Powerpipe and Steampipe.
cloudsploit - Cloud Security Posture Management (CSPM)
terraform-aws-secure-baseline - Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.
cloudsplaining - Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.
opencspm - Open Cloud Security Posture Management Engine
aws-sso-creds-tool - script to (almost) auto update aws sso credentials file
CIS-Ubuntu-20.04-Ansible - Ansible Role to Automate CIS v1.1.0 Ubuntu Linux 18.04 LTS, 20.04 LTS Remediation
jsplumb - Visual connectivity for webapps
terraform-security-scan - Run a security scan on your terraform with the very nice https://github.com/aquasecurity/tfsec