CybersecTools logoCybersecTools

The world's largest cybersecurity product directory. 8,700+ products, real market intelligence, and competitive insights to help you find, evaluate, and optimize your security stack.

Operated by:

Mandos Cyber

KVK: 97994448

Address: 124, 1230 AC, LOOSDRECHT, Netherlands

VAT: NL005301434B12

Copyright © 2026 - All rights reserved

DISCOVER
All CategoriesEnterprise ToolsCompare ToolsPopular ToolsAll ToolsEnterprise StacksFree ToolsAlternativesService ProvidersMarket MapBrowse by Use Case
TOP CATEGORIES
AI SecurityCloud SecurityEndpoint SecurityApplication SecurityNetwork SecurityIdentity & AccessData Security
SERVICES
Mandos ServicesMCP Access (AI Data)Get ListedBadges
LEARN
Shortlists: best tools by categoryBuying guidesGlossaryAll resourcesMethodology
COMPANY
AboutContact Usllms.txtTerms of ServicePrivacy Policy
CybersecTools logoCybersecTools
  • Map
  • AI Access

Cloud Security Tools 2026

Cloud security covers the tools that protect what you run in AWS, Azure, GCP, and the SaaS apps your business depends on: catching misconfigurations before attackers do, watching workloads at runtime, governing the identities and permissions that quietly became the real perimeter, and detecting and responding to threats inside cloud control planes. The space splits into two broad jobs. Posture work (CSPM, SSPM, and the consolidation play that is CNAPP) finds and fixes risk before it ships. Runtime and response work (CWPP, CADR, CDR, and Cloud Investigation and Response Automation) handles what is already live and what is actively happening. Around those sit the access and data layers: CASB for SaaS access, Serverless Security for functions, and Cloud Storage Security for the buckets and blobs where the data actually lives. If you own cloud risk, the work here is deciding how much you buy as one platform versus best-of-breed, and how you cover both infrastructure and SaaS without leaving gaps between them.

The most comprehensive Cloud Security directory, covering Cloud Application Detection and Response, Cloud Investigation and Response Automation, Cloud Security Posture Management, Cloud-Native Application Protection Platform, Container Security, Serverless Security, Cloud Access Security Broker, SSPM, CWPP, Cloud Storage Security. Filter by use case, pricing, or specialization, and compare tools side by side to find the right fit. Independent and vendor-neutral: our scores and rankings are earned, never bought — sponsored placement is always labeled.

We cover 338 Cloud Security tools, 98 free and 240 commercial.

Accuracy and depth improve over time. Last reviewed Oct 2026. Is something off? Reach out.

FEATURED

Strike48 Platform Logo
Strike48 Platform
  1. Home
  2. Categories
  3. Cloud Security

USE CASES

5G (2)AI Governance (2)AI Pentesting (1)AI SPM (1)AWS (97)AWS Security (5)Active Directory (1)Agentic AI Security (2)Alerting (7)Android Security (1)

New to this category? What is Cloud Security?

Cloud Custodian (c7n) Logo
Cloud Custodian (c7n)

Cloud Custodian is a YAML-based rules engine that manages and enforces security, compliance, and cost optimization policies across AWS, Azure, and GCP cloud environments in real-time.

Cloud Security Posture Management
Free
Ice Logo
Ice

Ice is an AWS cloud cost management tool that provides multi-level visibility into cloud spending and resource utilization to support informed reservation purchases and resource optimization decisions.

Cloud Security Posture Management
Free
Nuvola Logo
Nuvola

A cloud security analysis tool that creates digital twins of AWS environments using graph databases to identify attack paths and security misconfigurations through automated and manual rule-based assessments.

Cloud Security Posture Management
Free
Terraform Module: AWS Secure Baseline Logo
Terraform Module: AWS Secure Baseline

A Terraform module that establishes security baseline configurations for AWS accounts based on CIS benchmarks and AWS security best practices.

Cloud Security Posture Management
Free
AWS Auto Remediate Logo
AWS Auto Remediate

An automated AWS security compliance remediation system that uses Lambda functions and SQS queues to automatically fix security violations detected by AWS Config.

Cloud Security Posture Management
Free
ElectricEye Logo
ElectricEye

ElectricEye is a multi-cloud Python CLI tool that performs security posture management and attack surface monitoring across cloud service providers and SaaS platforms with over 1000 security checks mapped to 20+ compliance frameworks.

Cloud Security Posture Management
Free
AWS Log Logo
AWS Log

A command-line tool that shows configuration history and changes of AWS resources using AWS Config service.

Cloud Security Posture Management
Free
CloudTrail Partitioner Logo
CloudTrail Partitioner

CloudTrail Partitioner automates the creation and management of partitioned Athena tables for AWS CloudTrail logs with nightly partition updates.

Cloud Security Posture Management
Free
AWS Recon Logo
AWS Recon

A multi-threaded Ruby tool for comprehensive AWS security inventory collection that gathers detailed resource attributes, metadata, and policy information across AWS environments.

Cloud Security Posture Management
Free
aws-lint-iam-policies Logo
aws-lint-iam-policies

A command-line tool that performs automated IAM policy security linting across AWS accounts and organizations using AWS Access Analyzer validation.

Cloud Security Posture Management
Free
Cloud Inquisitor Logo
Cloud Inquisitor

Cloud Inquisitor is an AWS security tool that monitors resource ownership, detects domain hijacking, verifies security services, and manages IAM policies across multiple accounts.

Cloud Security Posture Management
Free
AWS Security Toolbox (AST) Logo
AWS Security Toolbox (AST)

A Docker container that bundles preinstalled AWS security tools for streamlined security operations and assessments in AWS environments.

Cloud Security Posture Management
Free
iam-lint Logo
iam-lint

A GitHub action that lints AWS IAM policy documents to identify security issues and misconfigurations with configurable severity levels and custom rules.

Cloud Security Posture Management
Free
Varna Logo
Varna

Varna is an AWS serverless security tool that monitors CloudTrail logs using Event Query Language to detect and alert on suspicious activities in cloud environments.

Cloud Application Detection and Response
Free
AWS Security Architectures Logo
AWS Security Architectures

A comprehensive AWS security automation toolkit that provides event monitoring, data protection, resource management, and security configuration validation across AWS environments.

Cloud Security Posture Management
Free
aws-fast-fixes Logo
aws-fast-fixes

A collection of automation scripts that quickly enable essential AWS security and compliance features that are not activated by default in AWS accounts.

Cloud Security Posture Management
Free
Cloud Reports Logo
Cloud Reports

A cloud security assessment tool that collects cloud resource information, analyzes it against best practices, and generates compliance reports in multiple formats.

Cloud Security Posture Management
Free
aws-security-viz Logo
aws-security-viz

A Ruby-based tool that creates visual diagrams of AWS EC2 security group configurations to help understand network access patterns and security relationships.

Cloud Security Posture Management
Free
Security Monkey Logo
Security Monkey

Security Monkey monitors AWS, GCP, and OpenStack environments for policy changes and insecure configurations, providing historical tracking and alerting capabilities through a centralized interface.

Cloud Security Posture Management
Free
Metabadger Logo
Metabadger

Metabadger automates the upgrade of AWS EC2 instances to use the more secure Instance Metadata Service v2 (IMDSv2) to prevent SSRF attacks and reduce attack surface.

Cloud Security Posture Management
Free
Antiope AWS Inventory & Compliance Framework Logo
Antiope AWS Inventory & Compliance Framework

An open-source framework that inventories and manages AWS resources across multiple accounts by collecting data via Cross Account Assume Roles and storing it in a centralized S3 bucket for analysis.

Cloud Security Posture Management
Free
rpCheckup Logo
rpCheckup

rpCheckup is an AWS resource policy security analysis tool that identifies public, external, intra-organizational, and private resource access patterns across AWS accounts.

Cloud Security Posture Management
Free
drydock Logo
drydock

A Python-based Docker security audit tool that performs CIS benchmark assessments with customizable profiles and JSON reporting capabilities.

Container Security
Free
Weave Scope Logo
Weave Scope

Weave Scope is a real-time visualization and monitoring tool that automatically maps Docker container infrastructures and microservices, providing interactive topology views and direct container management capabilities.

Container Security
Free
  • Previous
  • 10
  • 11
  • 12
  • 13
  • 14
  • More pages
  • 15
  • Next

Cloud Security Specializations

338 tools across 10 specializations · 98 free, 240 commercial

Cloud Application Detection and Response

Cloud Application Detection and Response (CADR) platforms for real-time threat detection, incident response, and security monitoring in cloud application environments.

Cloud Investigation and Response Automation

Cloud Investigation and Response Automation (CIRA) tools for automated incident investigation, threat hunting, and security response orchestration in cloud infrastructures.

Cloud Security Posture Management

Cloud Security Posture Management (CSPM) platforms for continuous cloud security monitoring, compliance checking, and misconfiguration detection across AWS, Azure, and GCP.

How to choose Cloud Security tools

  • Map the tool to a specific job before comparing vendors: posture (CSPM/SSPM/CNAPP), runtime (CWPP/CADR/CDR), access (CASB), or data (Cloud Storage Security). Overlapping pitches hide real coverage gaps.
  • Check actual multi-cloud depth, not a logo grid. Coverage for AWS, Azure, and GCP is rarely equal, and the cloud you use least is where the weakest support hurts most.
  • Decide your agent strategy early. Confirm whether the tool is agentless, agent-based, or both, and whether runtime depth matters enough to justify deploying agents on the workloads that need them.
  • Treat identity and permissions as a core requirement, not a bonus. The strongest cloud tools graph who and what can reach what, since over-permissioned roles cause more cloud breaches than novel exploits.
  • Separate posture from response. Finding misconfigurations is table stakes; weigh how the tool prioritizes by real exposure and whether it supports investigation and remediation through CIRA-style automation or your existing workflow.
  • Pressure-test the consolidation pitch against your team. A platform only pays off if your people will actually operate every module; otherwise a focused best-of-breed tool you fully use beats a suite you half-configure.

Articles About Cloud Security

Tool roundups, buying guides, and strategic analysis from the CybersecTools resource library.

Best Cloud Web Application and API Protection Tools in 2026

Compare the best cloud WAAP tools in 2026: Cloudflare WAF, Akamai, Imperva, F5, FortiWeb, Cisco, and Radware. Find the right fit for your stack.

Best Cloud Security Tools in 2026

Compare the best cloud security tools in 2026: Wiz, Microsoft Defender, CrowdStrike, Palo Alto, SentinelOne, Check Point, and Upwind. Find the right CNAPP.

Best Container Security Tools in 2026

Compare the best container security tools in 2026: image scanners, runtime protection, and Kubernetes security platforms reviewed for real-world deployment.

Best Digital Risk Protection Tools in 2026

The 7 best digital risk protection tools in 2026 reviewed by practitioners. Compare ZeroFox, SOCRadar, Rapid7, Cyberint, and more for dark web monitoring and brand protection.

Cloud Security Tools FAQ

Common questions about Cloud Security tools, selection guides, pricing, and comparisons.

Cloud security is the discipline and tooling for protecting infrastructure, applications, identities, and data hosted in public cloud and SaaS environments. It spans finding misconfigurations and excess permissions before they cause incidents, defending running workloads, governing access at the edge, and detecting and responding to threats inside cloud control planes. It differs from on-prem security because the attack surface is API-driven and changes by the minute.

Match it to your operating model. CNAPP consolidates CSPM, CWPP, and adjacent functions into one platform with shared context, which suits teams that want a single console and correlated findings across posture and runtime. Point tools win when one capability, say runtime detection or SaaS posture, has to be excellent and the rest is good enough. Watch for coverage gaps between vendors and the cost of stitching findings across separate consoles yourself.

Both manage posture, for different surfaces. CSPM (Cloud Security Posture Management) finds misconfigurations and risky settings in infrastructure like AWS, Azure, and GCP: open storage, weak IAM, exposed compute. SSPM (SaaS Security Posture Management) does the same job for SaaS applications like Microsoft 365, Salesforce, and Google Workspace: oversharing, risky OAuth grants, weak admin settings. Many programs need both because infrastructure tools rarely see inside SaaS.

Most mature programs run both. Agentless scanning (snapshot or API-based) gives fast, broad coverage with no deployment friction, ideal for posture and inventory across thousands of assets. Agent-based tooling gives deeper runtime visibility: live process activity, in-memory threats, real-time blocking. The practical question is which workloads justify an agent, and whether your chosen platform combines both views without forcing you to pick.

Open-source tools (cloud config scanners, IaC linters, runtime monitors) are genuinely useful and often the right starting point for posture checks and CI gating. They tend to fall short on multi-cloud correlation, identity graphing, managed threat detection, and the response automation larger estates need. The honest test is your estate size and team capacity: small footprints go far on open source, while broad multi-cloud and SaaS coverage usually justifies a commercial platform.

Have more questions? Browse our categories or search for specific tools.
Security Operations
SecureIntent Logo
SecureIntent
Data Protection
Fortra Logo
Fortra
Data Protection
Push Security Logo
Push Security
Endpoint Security
Lunar Logo
Lunar
Threat Intelligence
Hudson Rock Logo
Hudson Rock
Threat Intelligence
Daylight Security Logo
Daylight Security
Security Operations
Get Featured

Cloud-Native Application Protection Platform

Cloud-Native Application Protection Platforms (CNAPP) that integrate multiple cloud security capabilities for comprehensive protection of cloud-native applications and workloads.

Container Security

Container security tools for securing Docker containers, Kubernetes clusters, and containerized applications throughout the DevOps lifecycle.

Serverless Security

Serverless security tools for protecting AWS Lambda, Azure Functions, and other function-as-a-service (FaaS) deployments from security threats.

Cloud Access Security Broker

Cloud Access Security Broker (CASB) solutions that provide visibility, compliance, data security, and threat protection for cloud services and applications.

SSPM

SaaS Security Posture Management (SSPM) tools that assess and harden the security posture of SaaS applications, distinct from CSPM and CASB.

CWPP

Cloud Workload Protection Platform (CWPP) — standalone runtime security for CLOUD workloads: cloud VMs, containers, and serverless across AWS/Azure/GCP.

Cloud Storage Security

Cloud storage security tools that scan cloud object storage (S3, Azure Blob, GCS, EFS) for malware and sensitive data, providing in-tenant antivirus and content inspection of stored files.

Sponsored

Knocknoc Logo
Knocknoc
Network Security
Advertise Here

Most Upvoted Cloud Security Tools

  1. 1. CloudDefense.AI QINA0
  2. 2. Orca Security Platform1
  3. 3. ARMO1
  4. 4. SentinelOne Singularity Cloud Security0
  5. 5. ScubaGear0

TRENDING CATEGORIES

Penetration Testing
Penetration testing tools and PTaaS for point-in-time manual or assisted pentests that produce a findings report.
339
Digital Forensics
Digital forensics tools whose primary job is to collect, preserve, and analyze evidence after the fact.
255
Threat Intel Platforms
Threat Intelligence Platforms (TIP) that aggregate and operationalize intel, including IOC management and integration.
237
Honeypots & Deception
Honeypots and cyber deception solutions that simulate vulnerable systems to detect, divert, and analyze attacker activities in real time.
220
Vulnerability Assessment
Vulnerability assessment tools that scan, prioritize, and drive remediation programs across assets.
191
View All Categories →

POPULAR

RoboShadow Logo
RoboShadow
Vulnerability Assessment
OSINTLeak Real-time OSINT Leak Intelligence Logo
OSINTLeak Real-time OSINT Leak Intelligence
Digital Risk Protection
TestSavant AI Security Assurance Platform Logo
TestSavant AI Security Assurance Platform
AI Red Teaming
Cybersec Feeds Logo
Cybersec Feeds
Threat Intel Feeds
DeHashed Logo
DeHashed
Digital Risk Protection
View Popular Tools →