Perimeterator Logo

Perimeterator

0
Free
Visit Website

Perimeterator is a small project intended to allow for continuous auditing of internet facing AWS services. It can be quickly deployed into AWS and will periodically enumerate internet-facing IP addresses for a number of commonly misconfigured AWS resources. The results from this enumeration process are pushed into a work queue for scanning by external scanner 'workers' in order to locate open network services. Scanner 'workers' can be deployed anywhere, and are intended to be deployed into non-trusted networks in order to provide a representation of access to services from the "general internet". Currently, the following AWS resource types are supported: EC2 ELB ELBv2 RDS ES All communication between Perimeterator components occurs asynchronously through the use of AWS SQS queues. Demo Getting Started / Deployment Perimeterator requires a few components in order to function. However, in order to make getting started as easy as possible, a number of Terraform configs have been provided inside of the terraform/ directory. To get started, please see the terraform/README.md file. Components Perimeterator has a number of components, due to its distributed nature. A brief overview of each component is provided below: * Scanner: Responsible for scanning IP addresses for open network services. * Worker: Responsible for processing work items from the SQS queue. * SQS Queue: Used to communicate between components.

FEATURES

ALTERNATIVES

Tool for assessing compliance and running vulnerability scans on Docker images.

Cloud Custodian (c7n) is a rules engine for managing public cloud accounts and resources with a focus on security, compliance, and cost optimization.

A fully managed service that securely stores, rotates, and manages sensitive data such as database credentials and API keys.

Open-source project for detecting security risks in cloud infrastructure accounts with support for AWS, Azure, GCP, OCI, and GitHub.

A comprehensive cloud security platform that combines vulnerability management, compliance monitoring, and automated remediation capabilities through an agentless architecture to protect cloud infrastructure and applications.

Commercial

AWS Scout2 is a security tool for AWS administrators to assess their environment's security posture.

Automated script for creating a vulnerable Azure cloud lab to train offensive security skills.

S3Scanner scans for misconfigured S3 buckets across S3-compatible APIs, identifying potential security vulnerabilities and data exposure risks.

PINNED