{"repo":"raajheshkannaa/attack-surface-management","free":true,"listed":false,"github":"https://github.com/raajheshkannaa/attack-surface-management","clone":"git clone https://github.com/raajheshkannaa/attack-surface-management.git","description":"Continuous External Attack Surface Discovery & Vulnerability Scanning Across AWS Organizations — Python CDK","language":"Python","stars":15,"topics":["aws","security","nmap","attacksurface","docker","automation","lightsail","rds","ec2","ebs"],"license":"MIT","category":"security-tools","readme_excerpt":"Attack Surface Management Continuous External Attack Surface Discovery & Vulnerability Scanning Across AWS Organizations Enumerate every public-facing IP across all AWS accounts in your Organization, scan with nmap + Vulners, and alert on new open ports via Slack. Built entirely in Python CDK — deploy with a single cdk deploy . Architecture The Problem You can't protect what you can't see. AWS makes it trivially easy to expose resources — a public RDS instance, an overlooked Elastic IP, a Lightsail box someone forgot about. AWS Inspector only covers EC2. Commercial ASM tools (Censys, Shodan, Mandiant Advantage) cost $20K+/year. This project gives you Organization-wide external asset discovery and vulnerability scanning for the cost of a few Lambda invocations and a NAT Gateway. How It Works Three Lambda functions form a fan-out pipeline: Lambda Runtime Role What It Does -------- --------- ------ ------------- asm-1 Python 3.12 Orchestrator Assumes into Org account, lists all AWS accounts, invokes asm-2 per account (async) asm-2 Python 3.12 Enumerator Assumes spoke role in target account, enumerates 10 services for public IPs, invokes asm-3 per IP (async) asm-3 Docker (nmap) Scanner Runs nmap --script vuln against each IP, deduplicates via DynamoDB, alerts Slack Services Enumerated EC2 (instances + Elastic IPs), Classic ELB, ALB/NLB, Elastic Beanstalk, API Gateway, RDS, Redshift, CloudFront, Lightsail (instances + load balancers), OpenSearch/Elasticsearch Fan-Out Math If you h","default_branch":null,"files":null,"tree":[],"storefront":"/r/raajheshkannaa","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/raajheshkannaa/attack-surface-management/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}