Azucar is a multi-threaded plugin-based tool designed to assess the security of Azure Cloud environments. It provides detailed information on various assets in an Azure subscription without making any changes to the deployed assets. The tool supports Windows OS due to its use of the .NET ADAL library for authentication and REST API calls. Features include retrieving attributes on computers, users, groups, contacts, events from Azure Active Directory, searching for High Level Accounts in a specific Azure Tenant, multi-threading support, and plugin support. Azucar supports assets such as Azure SQL Databases (including MySQL and PostgreSQL), Azure Active Directory, Storage Accounts, Classic Virtual Machines, Virtual Machines V2, Security Status, Security Policies, Role Assignments (RBAC), Missing Security Patches, Missing Security Baseline, Web Application Firewall, Network Security Groups, Classic Endpoints, Azure Security Alerts, and Azure KeyVault.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Automated script for creating a vulnerable Azure cloud lab to train offensive security skills.
Automate actions on Security Command Center findings with automated disk snapshots, IAM grant revocation, and more.
Open-source project for detecting security risks in cloud infrastructure accounts with support for AWS, Azure, GCP, OCI, and GitHub.
Discover and understand the Docker Layer 2 ICC Bug and its implications on inter-container communication.
Learn how to secure applications in Kubernetes Engine by granting varying levels of privilege based on requirements.
Cloud Security Suite (cs-suite) - Version 3.0 Usage for cloud security audits on AWS, GCP, Azure, and DigitalOcean.
Tool for assessing compliance and running vulnerability scans on Docker images.
A framework to analyze container images and gather useful information.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.