{"repo":"gebalamariusz/cloud-audit","free":true,"listed":false,"github":"https://github.com/gebalamariusz/cloud-audit","clone":"git clone https://github.com/gebalamariusz/cloud-audit.git","description":"Fast, opinionated AWS security scanner. Curated checks. Zero noise. Copy-paste fixes.","language":"Python","stars":69,"topics":["audit","aws","cli","cloud-security","compliance","devops","python","security","aws-audit","aws-security"],"license":"MIT","category":"security-tools","readme_excerpt":"cloud-audit English 简体中文 Find AWS attack paths, IAM escalation routes, and the fixes that matter most. Open-source, read-only AWS security scanner. It correlates findings into attack chains, ranks fixes by how many chains they break, and ships an AWS CLI + Terraform fix with every finding . No agent, no infrastructure, nothing written to your account. Quick Start - What You Get - Installation - What's Checked - Documentation Quick Start No AWS account handy? Run a full sample report offline: cloud-audit is read-only . It never modifies your infrastructure; SecurityAudit is enough (permissions). Example Output Preview a fix before you touch anything: What You Get - Attack chains // 31 rules correlate individual findings into exploitable paths (MITRE ATT&CK + pathfinding.cloud). docs - Root-cause fixes // groups findings by shared cause and ranks them: \"fix 4 things, break 22 chains,\" with a what-if simulate to preview impact. docs - IAM privilege escalation // 64 methods across 9 categories, including lateral movement through the AssumeRole graph. docs - Blast radius // walk outward from any resource to see what an attacker reaches; export JSON to the live visualizer. docs - Proof Mode // scan --verify checks each escalation path against the IAM policy simulator (read-only) and flags the ones the principal can actually perform. docs - Data perimeter // resource-policy checks for confused-deputy and cross-org exposure, evaluating condition values (not just their presence). docs","default_branch":null,"files":null,"tree":[],"storefront":"/r/gebalamariusz","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/gebalamariusz/cloud-audit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}