Cloud Custodian, also known as c7n, is a rules engine for managing public cloud accounts and resources. It allows users to define policies to enable a well-managed cloud infrastructure, that's both secure and cost-optimized. It consolidates many of the adhoc scripts organizations have into a lightweight and flexible tool, with unified metrics and reporting. Custodian can be used to manage AWS, Azure, and GCP environments by ensuring real-time compliance to security policies (like encryption and access requirements), tag policies, and cost management via garbage collection of unused resources and off-hours resource management. Custodian also supports running policies on infrastructure as code assets to provide feedback directly on developer workstations or within CI pipelines. Custodian policies are written in simple YAML configuration files that enable users to specify policies on a resource type (EC2, ASG, Redshift, CosmosDB, PubSub Topic) and are constructed from a vocabulary of filters and actions. It integrates with the cloud-native serverless capabilities of each provider to provide for real-time enforcement of policies with built-in provisioning.
FEATURES
SIMILAR TOOLS
Generate Amazon GuardDuty findings related to real AWS resources with multiple tests available.
A tool to find S3 buckets from HTML, JS, and bucket misconfiguration testing
A Python script that lists all main resources of your AWS account, helping you find resources that affect billing and/or security.
Azucar is a multi-threaded plugin-based tool for assessing Azure Cloud security.
Show the history and changes between configuration versions of AWS resources
A multi-threaded AWS security-focused inventory collection tool with comprehensive resource coverage and efficient data collection methods.
Converts the format of various S3 buckets for bug bounty and security testing.
Multi-cloud OSINT tool for enumerating public resources in AWS, Azure, and Google Cloud.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.