Skip to content

gebalamariusz/cloud-audit

Vulnerability Scanning

Open‑source, read‑only AWS security scanner that discovers attack paths, IAM escalation routes and provides ready‑to‑apply CLI/Terraform fixes.

Python Latest v2.4.0 · 26d ago Security brief →

Features

  • Detects and correlates AWS findings into exploitable attack chains (MITRE ATT&CK).
  • Ranks root‑cause fixes by how many chains they break, with a what‑if simulation.
  • Scans for IAM privilege escalation paths across AssumeRole graphs.
  • Provides an interactive blast‑radius visualizer to map reachable resources.
  • Generates per‑finding AWS CLI commands and Terraform remediation code.

Recent releases

View all 29 releases →
Review required
v2.4.0 New feature
Auth RBAC

Data Perimeter Scanner + Proof Mode

Review required
v2.3.1 New feature
Auth RBAC Dependencies

DynamoDB checks + S3 validation + Config hardening

Review required
v2.3.0 New feature
Auth RBAC

Blast Radius CLI + exposure

Review required
v2.2.1 Breaking risk
Auth

SES escalation logic change

Review required
v2.2.0 New feature
Auth RBAC

Threat Feed v1

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
66
Forks
13
Languages
Python Jinja HTML

Install & Platforms

Install via
pip

Beta — feedback welcome: [email protected]