Tools
Contents
This is where I maintain a curated list of tools that were useful for me in the past.
Amazon Web Services (AWS)
Development
- bridgecrewio/checkov - Security scanning for Terraform/Cloudformation/K8s templates
- salesforce/policy_sentry - Generate least-priviledge IAM policies without having to dig the entire AWS IAM permission model.
Security Scanners
- salesforce/metabadger - Find and remediate AWS instances using IMDSv1
- salesforce/cloudsplaining - Scans an AWS account and generates a risk report.
- prowler-cloud/prowler - Scans an AWS account and finds breaches on controls for common security frameworks like CIS, PCI-DSS, ISO27001, GDPR, HIPAA, FFIEC, SOC2, AWS FTR, ENS, etc…