Skip to content

A curated list of cloud security tools for AWS, Azure, GCP, and Kubernetes

License

Notifications You must be signed in to change notification settings

Su1ph3r/awesome-cloud-security

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Awesome Cloud Security Awesome

A curated list of cloud security tools for AWS, Azure, GCP, and Kubernetes.

Whether you're a penetration tester, cloud security engineer, DevSecOps professional, or security researcher, this list provides tools for offensive security, defensive security, compliance, and IAM analysis.

Contents

Multi-Cloud Security

  • Nubicustos - Unified security platform orchestrating 24+ tools with attack path analysis and compliance across AWS, Azure, GCP, and Kubernetes.
  • Prowler - Security assessment tool for AWS, Azure, GCP, and Kubernetes with CIS benchmark checks.
  • ScoutSuite - Multi-cloud security auditing tool supporting AWS, Azure, GCP, Alibaba Cloud, and Oracle Cloud.
  • CloudSploit - Cloud security configuration scanner for AWS, Azure, GCP, and Oracle Cloud.
  • CloudQuery - Open source cloud asset inventory with SQL-based policy engine.
  • Steampipe - Query cloud APIs using SQL with pre-built compliance mods.
  • Cloud Custodian - Rules engine for cloud security, cost optimization, and governance.
  • Magpie - Cloud security posture management with data discovery.
  • Cartography - Graph-based asset inventory and relationship mapping.
  • cloudlist - Multi-cloud asset listing tool.
  • Resoto - Infrastructure inventory with search and analytics.

Attack Path Analysis

  • CloudFox - AWS attack surface enumeration for penetration testers.
  • PMapper - AWS IAM privilege escalation path finder using graph analysis.
  • Cloudmapper - AWS environment visualization and analysis.
  • AzureHound - Azure data collector for BloodHound attack path analysis.

AWS Security

Offensive

  • Pacu - AWS exploitation framework for penetration testing.
  • aws_pwn - Collection of AWS penetration testing tools.
  • Endgame - AWS resource policy exploitation tool for privilege escalation.
  • Weirdaal - AWS attack library.
  • ccat - Cloud Container Attack Tool.
  • Nimbostratus - AWS security assessment tool.

Defensive

IAM

S3

Azure Security

Offensive

  • ROADtools - Azure AD exploration framework.
  • MicroBurst - PowerShell toolkit for Azure security.
  • Stormspotter - Azure Red Team tool for graphing resources.
  • PowerZure - PowerShell framework for Azure security.
  • AADInternals - Azure AD administration PowerShell module.

Defensive

  • ScubaGear - M365 security configuration assessment.
  • Monkey365 - Azure and Microsoft 365 security scanner.

IAM

GCP Security

Offensive

Defensive

Container and Kubernetes Security

Image Scanning

  • Trivy - Comprehensive vulnerability scanner for containers.
  • Grype - Vulnerability scanner for container images.
  • Clair - Static analysis of container vulnerabilities.
  • Anchore - Container image analysis and policy enforcement.

Runtime Security

  • Falco - Cloud-native runtime security.
  • Tetragon - eBPF-based security observability.
  • KubeArmor - Container-aware runtime security.
  • Tracee - Linux runtime security with eBPF.

Kubernetes Audit

  • kube-bench - CIS Kubernetes Benchmark checks.
  • Kubescape - Kubernetes security platform with NSA and MITRE frameworks.
  • kube-hunter - Kubernetes penetration testing.
  • Polaris - Best practices validation.
  • Popeye - Kubernetes cluster sanitizer.
  • kube-linter - Static analysis for Kubernetes manifests.
  • kubeaudit - Audit Kubernetes clusters for security concerns.
  • Kubei - Kubernetes runtime vulnerability scanner.

IAM Analysis

Secrets Scanning

  • TruffleHog - 700+ secret detectors with API verification.
  • Gitleaks - Fast Git secrets scanner with extensive rule set.
  • detect-secrets - Secrets detection in codebases.
  • git-secrets - Prevent committing secrets to Git.
  • ggshield - GitGuardian CLI for secrets detection.
  • whispers - Static code analysis for secrets.

Compliance and Governance

  • OpenSCAP - Security Content Automation Protocol implementation.
  • InSpec - Infrastructure testing and compliance automation.

Infrastructure as Code Security

  • Checkov - Static analysis for Terraform, CloudFormation, Kubernetes, Helm, and ARM templates.
  • tfsec - Security scanner for Terraform code.
  • Terrascan - Static code analyzer for IaC with 500+ policies.
  • KICS - Infrastructure as Code scanner for security vulnerabilities.
  • Regula - Policy engine for Terraform and CloudFormation using Rego.

Serverless Security

  • Serverless Goat - OWASP serverless vulnerable application.
  • DVSA - Damn Vulnerable Serverless Application.

Training Labs

AWS

Azure

GCP

Kubernetes

Multi-Cloud

Contributing

Contributions welcome! Read the contribution guidelines first.