{"repo":"primait/nuvola","free":true,"listed":false,"github":"https://github.com/primait/nuvola","clone":"git clone https://github.com/primait/nuvola.git","description":null,"language":"Go","stars":144,"topics":["aws","cloud","golang","neo4j","redteaming","cloudsecurity","devops","devsecops"],"license":"GPL-3.0","category":"deployment-docker-iac","readme_excerpt":"nuvola nuvola (with the lowercase n) is a tool to dump and perform automatic and manual security analysis on AWS environments configurations and services using predefined, extensible and custom rules created using a simple Yaml syntax. The general idea behind this project is to create an abstracted digital twin of a cloud platform. For a more concrete example: nuvola reflects the BloodHound traits used for Active Directory analysis but on cloud environments (at the moment only AWS). The usage of a graph database also increases the possibility of finding different and innovative attack paths and can be used as an offline, centralised and lightweight digital twin. Quick Start Requirements - docker-compose installed - an AWS account configured to be used with awscli with full access to the cloud resources, better if in ReadOnly mode (the policy arn:aws:iam::aws:policy/ReadOnlyAccess is fine) Setup 1. Clone the repository 2. Create and edit , if required, the .env file to set your DB username/password/URL You may need to edit the size of the memory allocated to Neo4j in you run the tool in a low-RAM device. 3. Start the Neo4j docker instance 4. Build the tool Usage 1. Firstly you need to dump all the supported AWS services configurations and load the data into the Neo4j database: 2. To import a previously executed dump operation into the Neo4j database: 3. To only perform static assessments on the data loaded into the Neo4j database using the predefined ruleset: 4. Or use Neo4j B","default_branch":null,"files":null,"tree":[],"storefront":"/r/primait","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/primait/nuvola/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}