auspex Logo

auspex

A graph-based tool for visualizing AWS access permissions and resource relationships to identify potential attack paths and privilege escalation opportunities.

973
Cloud Security
Free
Visit website
0

auspex Description

auspex is a graph-based visualization tool designed for analyzing AWS environments to understand effective access permissions and resource relationships. The tool resolves AWS policy information to determine which actions can affect specific resources within an AWS account. It takes into account how different actions may be combined to create potential attack paths, providing security teams with visibility into privilege escalation opportunities and lateral movement possibilities. auspex consists of two main components: an ingestor that collects AWS account data, and a web interface that enables interactive exploration of the collected information. The tool presents this data in a graph format, making it easier to visualize complex relationships between AWS resources, permissions, and potential security risks. The tool requires Docker for installation and can be deployed on Linux or macOS systems. It helps security professionals understand the effective permissions landscape within their AWS infrastructure by mapping out how IAM policies, resource-based policies, and service configurations interact to create access patterns.

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

10
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

5
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →