This repository contains some tools to be used by forensics teams to collect evidence from cloud platforms. Currently, Google Cloud Platform, Microsoft Azure, and Amazon Web Services are supported. It consists of one module called libcloudforensics which implements functions that can be desirable in the context of incident response in a cloud environment, as well as a CLI wrapper tool for these functions. Documentation can be found on the ReadTheDocs page. Quick access: Installation User Manual How to contribute
FEATURES
SIMILAR TOOLS
A cloud native security platform that uses behavioral fingerprinting and runtime verification to detect threats across Kubernetes environments, cloud infrastructure, and software supply chains.
Cloud Custodian (c7n) is a rules engine for managing public cloud accounts and resources with a focus on security, compliance, and cost optimization.
A project that sets up partitioned Athena tables for CloudTrail logs and updates partitions nightly.
Access Undenied parses AWS AccessDenied CloudTrail events, explains the reasons for them, and offers actionable fixes.
Open source multi-cloud security-auditing tool for assessing security posture of cloud environments.
Open-source cloud-agnostic resource manager for analyzing and managing cloud cost, usage, security, and governance.
A framework to analyze container images and gather useful information.
Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.