{"repo":"404tk/cloudtoolkit","free":true,"listed":false,"github":"https://github.com/404tk/cloudtoolkit","clone":"git clone https://github.com/404tk/cloudtoolkit.git","description":"Authorized cloud adversary simulation and validation toolkit","language":"Go","stars":108,"topics":["cloud-security","alibabacloud","aws","huaweicloud","jdcloud","tencentcloud","ucloud","volcengine"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"CloudToolKit English 简体中文 Multi-cloud defensive validation toolkit for CSPM / CNAPP detection, telemetry, and investigation workflows in authorized environments. CloudToolKit gives security teams a practical way to verify whether cloud controls are discoverable, detectable, alertable, and investigable before those gaps matter in production. Why CloudToolKit Advantage What it gives defenders --- --- 9-cloud coverage One workflow across major global and China cloud providers. Asset-first inventory Hosts, databases, buckets, domains, accounts, logs, SMS assets, and billing-plane signals where supported. Validation payloads Focused checks for identity lifecycle, credential lifecycle, role bindings, storage exposure, audit events, instance command telemetry, and database account changes. Replay mode demo drives providers against in-memory replay fixtures, so detection logic can be tested without live cloud calls. Conservative claims Capabilities are advertised only when drivers, replay paths, and focused tests are in place. Capability Matrix Every provider supports cloudlist asset enumeration. Asset categories include host / database / bucket / domain / account / log / sms / balance where the cloud has a native equivalent. Validation payload coverage: Cloud iam bucket event cmd rds role acl cred &nbsp; AWS ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ &nbsp; Azure ✓ — ✓ ✓ ✓ ✓ ✓ ✓ &nbsp; GCP ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ &nbsp; Alibaba ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ &nbsp; Tencent ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ &nbsp; Huawei ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ &nbsp; Volcen","default_branch":null,"files":null,"tree":[],"storefront":"/r/404tk","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/404tk/cloudtoolkit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}