Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities. This extension uses Shodan to scan for cloud buckets and then uses Burp's proxy to test for vulnerabilities. This extension is useful for identifying potential security risks in cloud infrastructure and testing for vulnerabilities. Note: This extension requires a Shodan API key and a Burp proxy setup.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
An open-source security tool for AWS, Azure, Google Cloud, and Kubernetes security assessments and audits.
A command-line tool to get valuable information out of AWS CloudTrail and a general purpose toolbox for working with IAM policies
S3Scanner scans for misconfigured S3 buckets across S3-compatible APIs, identifying potential security vulnerabilities and data exposure risks.
AWS Cloud Security offers security services and compliance tools for securing data and applications on AWS.
Docker security audit tool with custom audit profiles and JSON report generation based on CIS Docker 1.6 Benchmark.
A framework to analyze container images and gather useful information.
A tool that discovers all AWS resources created in an account
Cloud Custodian (c7n) is a rules engine for managing public cloud accounts and resources with a focus on security, compliance, and cost optimization.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.