cloud-security

Open-source projects categorized as cloud-security

Top 23 cloud-security Open-Source Projects

  • Wazuh

    Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

  • Project mention: Exclude certain CIS (sca) rules from agents | /r/Wazuh | 2023-12-11

    There is currently no feature for excluding specific SCA rules however this feature has been requested here and would be added to the roadmap for future releases.

  • terrascan

    Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

  • Project mention: Cloud Security and Resilience: DevSecOps Tools and Practices | dev.to | 2024-05-01

    2. Terrascan: https://github.com/tenable/terrascan Terrascan detects security vulnerabilities and compliance violations across your IaC. Supports multiple cloud providers, ensuring that your infrastructure complies with security best practices.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • kubernetes-goat

    Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

  • consoleme

    A Central Control Plane for AWS Permissions and Access

  • Project mention: Launch HN: Slauth (YC S22) – auto-generate secure IAM policies for AWS and GCP | news.ycombinator.com | 2023-12-04

    Why are you using (very expensive) GPT, or any LLM for that matter, when this was already a solved problem using rulesets? Netflix for example has open source that does this already: https://github.com/Netflix/consoleme

    Instead of analyzing your code, you just run your code with no permissions and it automatically detects permission failures and thens open those permissions, with a UI showing you what it did so you can remove any permissions you don't want.

    That actually seems much more secure than trying to divine the rules from reading the code.

    What value is the LLM adding here?

  • awesome-cloud-security

    🛡️ Awesome Cloud Security Resources ⚔️

  • cloudfox

    Automating situational awareness for cloud penetration tests.

  • stratus-red-team

    :cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  • hackingthe.cloud

    An encyclopedia for offensive and defensive security knowledge in cloud native technologies.

  • Project mention: Cloud penetration testing courses | /r/cybersecurity | 2023-12-11

    It’s not quite a course, but Hacking the Cloud has a ton of educational content on cloud pentesting. It leans more towards AWS. https://hackingthe.cloud

  • veinmind-tools

    veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

  • matano

    Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

  • Project mention: Cisco Acquires Splunk | news.ycombinator.com | 2023-09-21

    sorry thats https://matano.dev

  • awesome-aws-security

    Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security

  • paralus

    All-in-one Kubernetes access manager. User-level credentials, RBAC, SSO, audit logs.

  • granted

    The easiest way to access your cloud.

  • Project mention: Ask HN: How do you manage many profiles and credentials for cloud tooling? | news.ycombinator.com | 2023-10-03

    You're going to love https://granted.dev. It can be extended further, as we've done internally: https://www.duckbillgroup.com/blog/overhauling-aws-account-a...

  • constellation

    Constellation is the first Confidential Kubernetes. Constellation shields entire Kubernetes clusters from the (cloud) infrastructure using confidential computing.

  • Project mention: Using "Confidential Computing" with Hetzner? (Intel SGX/TDX, AMD SEV/SNP) | /r/hetzner | 2023-05-16

    A lot happening in Europe, Enclaive provides encrypting containers (GitHub), Edgeless Systems provides a whole encrypted k8s with constellation (GitHub), then there are other players like scontain and secustack.

  • ElectricEye

    ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

  • SkyArk

    SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

  • awesome-cloud-security

    A curated list of awesome cloud security blogs, podcasts, standards, projects, and examples. (by Funkmyster)

  • stackql

    Query, provision and operate Cloud and SaaS resources and APIs using an extensible SQL based framework

  • Project mention: Cloud Tools You Probably Haven't Heard Of | dev.to | 2024-03-31

    Like Steampipe's revolutionary approach, StackQL harnesses the power of SQL to query your resources seamlessly. Moreover, it empowers you to utilize SQL syntax for querying and creating resources.

  • BucketLoot

    BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text.

  • Project mention: Open source S3 bucket scanner for secrets and assets | news.ycombinator.com | 2023-10-11
  • MAAD-AF

    MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

  • tfquery

    tfquery: Run SQL queries on your Terraform infrastructure. Query resources and analyze its configuration using a SQL-powered framework.

  • iamzero

    Identity & Access Management simplified and secure.

  • varc

    Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use when investigating a security incident.

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

cloud-security related posts

  • Acquisitions lead to struggles for Windows and Linux device management

    1 project | news.ycombinator.com | 24 Jan 2024
  • Unified analytics and IaC framework for cloud, IdP, and SaaS providers using SQL

    4 projects | news.ycombinator.com | 6 Oct 2023
  • OpenSource Mobile Device Management

    1 project | /r/opensource | 26 Jun 2023
  • Anyone using Fleet? Thoughts?

    1 project | /r/msp | 25 May 2023
  • Using "Confidential Computing" with Hetzner? (Intel SGX/TDX, AMD SEV/SNP)

    1 project | /r/hetzner | 16 May 2023
  • Mögliche Lösungen zu selbstzerstörenden Umgebungen mit einem Trigger

    2 projects | /r/de_EDV | 21 Apr 2023
  • Where are you hosting your Managed Kubernetes and why?

    1 project | /r/kubernetes | 5 Mar 2023
  • A note from our sponsor - InfluxDB
    www.influxdata.com | 10 May 2024
    Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality. Learn more →

Index

What are some of the best open-source cloud-security projects? This list will help you:

Project Stars
1 Wazuh 9,264
2 terrascan 4,518
3 kubernetes-goat 3,882
4 consoleme 3,066
5 awesome-cloud-security 1,910
6 cloudfox 1,800
7 stratus-red-team 1,621
8 hackingthe.cloud 1,518
9 veinmind-tools 1,471
10 matano 1,357
11 awesome-aws-security 1,118
12 paralus 932
13 granted 910
14 constellation 870
15 ElectricEye 864
16 SkyArk 828
17 awesome-cloud-security 562
18 stackql 434
19 BucketLoot 337
20 MAAD-AF 333
21 tfquery 325
22 iamzero 236
23 varc 232

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com