ScubaGear Logo

ScubaGear

0
Free
Visit Website

ScubaGear is an assessment tool designed to verify the configuration of Microsoft 365 (M365) tenants against the Secure Cloud Business Applications (SCuBA) Security Configuration Baseline documents. The tool operates in three main steps: 1. It uses PowerShell to query M365 APIs for various configuration settings. 2. It employs Open Policy Agent (OPA) to compare these settings against Rego security policies based on the baseline documents. 3. It generates reports in HTML, JSON, and CSV formats to present the results of the comparison. ScubaGear is primarily intended for M365 administrators who want to assess their tenant environments against CISA Secure Configuration Baselines. It can be installed from PSGallery and requires certain dependencies and permissions to function correctly. The tool supports assessment of multiple M365 products and can be run with specific parameters or using a configuration file. It also includes features for troubleshooting common issues related to multiple tenants, Defender, Exchange Online, Power Platform, Microsoft Graph, and proxy configurations.

FEATURES

ALTERNATIVES

A cloud-native application protection platform that provides comprehensive security monitoring, vulnerability management, and threat detection for cloud environments and container workloads.

Commercial

A tool for spinning up insecure AWS infrastructure with Terraform for training and security assessment purposes.

A Python script to test the security of AWS S3 buckets

A Lambda Function that disables AWS IAM User Access Keys after a set amount of time to reduce the risk associated with old access keys.

A customized AWS EKS setup for PCI-DSS, SOC2, and HIPAA compliance

A Terraform module to set up a secure AWS account configuration baseline

A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

Comprehensive set of security controls for various AWS services to ensure a secure cloud environment.

PINNED