Skip to content

gebalamariusz/cloud-audit

Vulnerability Scanning

Open-source AWS security scanner with attack chain detection, breach cost estimation, and copy-paste remediation (CLI + Terraform). 47 checks, 16 attack chain rules. First free standalone AWS security MCP server.

Python Latest v2.3.1 · 8d ago Security brief →

Features

  • Detect AWS attack paths and IAM escalation routes
  • Prioritize fixes based on impact (Blast Radius)
  • Simulate remediation effects before applying changes

Recent releases

View all 28 releases →
Review required
v2.3.1 New feature
Auth RBAC Dependencies

DynamoDB checks + S3 validation + Config hardening

Review required
v2.3.0 New feature
Auth RBAC

Blast Radius CLI + exposure

Review required
v2.2.1 Breaking risk
Auth

SES escalation logic change

Review required
v2.2.0 New feature
Auth RBAC

Threat Feed v1

Review required
v2.1.0 New feature
Auth RBAC

IAM privilege escalation detections

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
58
Forks
13
Languages
Python Jinja HTML

Install & Platforms

Install via
pip

Beta — feedback welcome: [email protected]