auspex is a graph-based tool for visualizing effective access and resource relationships within AWS. It resolves policy information to determine what actions affect which resources, while taking into account how these actions may be combined to produce attack paths. Getting Started Installation Usage Contributing License For more information, checkout the awspx Wiki Getting Started For detailed installation instructions, usage, and answers to frequently asked questions, see sections: Setup; Data Collection and Exploration; and FAQs, respectively. Installation awspx can be installed on either Linux or macOS. In each case Docker is required. Clone this repo git clone https://github.com/FSecureLABS/awspx.git Run the INSTALL script cd awspx && ./INSTALL Usage awspx consists of two main components: the ingestor, which collects AWS account data; and the web interface, which allows
FEATURES
SIMILAR TOOLS
Cloud security platform that provides configuration monitoring, compliance management, and security analysis across multi-cloud environments.
CLI tool for deleting AWS resources in bulk with inspecting functionality.
A tool that discovers all AWS resources created in an account
A fully managed service that securely stores, rotates, and manages sensitive data such as database credentials and API keys.
Access Undenied parses AWS AccessDenied CloudTrail events, explains the reasons for them, and offers actionable fixes.
Detect off-instance key usage in AWS by analyzing CloudTrail files locally.
A command line tool that counts Amazon resources across regions and displays the results in a friendly format.
Analyzes CloudTrail data of a given AWS account and generates a summary of recently active IAM principals, API calls they made, as well as regions, IP addresses and user agents they used.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.