Skip to content

Add cloud-audit - AWS security scanner with Terraform remediation#1774

Open
gebalamariusz wants to merge 1 commit intoanalysis-tools-dev:masterfrom
gebalamariusz:add-cloud-audit
Open

Add cloud-audit - AWS security scanner with Terraform remediation#1774
gebalamariusz wants to merge 1 commit intoanalysis-tools-dev:masterfrom
gebalamariusz:add-cloud-audit

Conversation

@gebalamariusz
Copy link

Adds cloud-audit to the Cloud/Terraform category.

cloud-audit is an open-source AWS security scanner (MIT license) that generates Terraform remediation code for every finding. Key features:

  • 47 curated checks covering IAM, S3, EC2, RDS, VPC, Lambda, KMS
  • Each finding includes both AWS CLI and Terraform fix code
  • Attack chain detection (correlates findings into multi-step attack paths)
  • Diff command for tracking security posture changes
  • SARIF output for GitHub Code Scanning
  • Tags: cloud, terraform, configmanagement

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant