Scanning for AWS Security Issues with Trivy

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • cargo-auditable

    Make production Rust binaries auditable

  • steampipe

    Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.

  • Readers may also enjoy Steampipe [1]. It's an open source "ops as code" CLI to query 83+ services (AWS, GitHub, Terraform, etc) with SQL [2] that comes with hundreds of ready to use benchmarks (CIS, NIST, Cost) and dashboards built in HCL [3]. The AWS Compliance mod [4] and Trivy plugin [5] are specific examples. (Disclaimer - I'm a lead on the project.)

    1 - https://steampipe.io

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • steampipe-plugin-trivy

    Use SQL to instantly query advisories, vulnerabilities, packages, findings and more using Trivy. Open source CLI. No DB required.

  • steampipe-mod-aws-compliance

    Run individual controls or full compliance benchmarks for CIS, PCI, NIST, HIPAA and more across all of your AWS accounts using Powerpipe and Steampipe.

  • cloudquery

    The open source high performance ELT framework powered by Apache Arrow

  • Shameless plug, you can also enjoy CloudQuery (https://github.com/cloudquery/cloudquery) where we take a more ELT approach so you can use plain SQL for policies (https://github.com/cloudquery/cloudquery/tree/main/plugins/s...) and then use any BI tools for visualization and monitoring (https://github.com/cloudquery/cloudquery/tree/main/plugins/s...).

    Shout out to steampipe bellow as a similar project though that takes a more real-time approach rather then ELT which has it's use-cases as well.

  • ScoutSuite

    Multi-Cloud Security Auditing Tool

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts