How to do AWS security assesment?

This page summarizes the projects mentioned and recommended in the original post on /r/u_athanielx

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • prowler

    Discontinued Prowler is an Open Source security tool to perform AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It contains more than 240 controls covering CIS, PCI-DSS, ISO27001, GDPR, HIPAA, FFIEC, SOC2, AWS FTR, ENS and custom security frameworks. [Moved to: https://github.com/prowler-cloud/prowler] (by toniblyx)

  • https://github.com/toniblyx/prowle (it's look like huge checklist)

  • ScoutSuite

    Multi-Cloud Security Auditing Tool

  • https://github.com/nccgroup/ScoutSuite (I used it for GCP one time, but I can't say if it good for AWS)

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • bucketeer

    Bucketeer is a small script that builds off the useful Sublist3r tool. The Tool tries to identify S3 Buckets and other useful subdomain information, that is used to perform subdomain takeover attacks.

  • s3audit-ts

    Discontinued CLI tool for auditing S3 buckets

  • https://github.com/scalefactory/s3audit (it's look intersting, because I need to identify if we have open buckets)

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts