Cloud Security Tools

Discover and compare 596 cloud security solutions for AWS, Azure, GCP and multi-cloud environments.

Cloud Container Attack Tool (CCAT)

Cloud Container Attack Tool (CCAT)

Penetration Testing Tools

A tool for testing security of container environments, particularly in cloud settings.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Bridgecrew

Bridgecrew

DevSecOps & Pipeline Security

Bridgecrew automates the identification and remediation of misconfigurations in cloud infrastructure, leveraging its open-source tool Checkov for static analysis of IaC templates.

Multi-Cloud
Proprietary
Cloud Service Only
Azucar

Azucar

Archived
Security Assessment & Audit

Security auditing tool for Azure environments

Azure
Open Source
Self Hosted Only
Mend.io

Mend.io

DevSecOps & Pipeline Security

Mend.io is a platform that integrates security into the software development lifecycle, focusing on open-source dependencies and codebases.

Multi-Cloud
Proprietary
Cloud Service Only
Leonidas

Leonidas

Security Training & Simulation

Automated Attack Simulation in the Cloud, complete with detection use cases.

AWS
Open Source
Cloud Service Only
Checkmarx SAST

Checkmarx SAST

DevSecOps & Pipeline Security

A static application security testing tool that identifies and mitigates security vulnerabilities early in the software development life cycle.

Multi-Cloud
Proprietary
Cloud Service Only
Selefra

Selefra

Compliance & Governance

The open-source policy-as-code software that provides analysis for Multi-Cloud and SaaS environments, you can get insight with natural language (powered by OpenAI).

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Snyk Cloud

Snyk Cloud

DevSecOps & Pipeline Security

Snyk Cloud secures cloud environments by integrating security checks into the development lifecycle, automating scans and continuous monitoring of cloud configurations.

Multi-Cloud
Proprietary
Cloud Service Only
AWS WAF Sample

AWS WAF Sample

Archived
Threat Detection & Response

This repository contains example scripts and sets of rules for the AWS WAF service. Please be aware that the applicability of these examples to specific workloads may vary.

AWS
Open Source
Self Hosted + Cloud Options
Snyk Cloud Security

Snyk Cloud Security

DevSecOps & Pipeline Security

A platform for securing cloud-native applications and infrastructure by integrating security into the software development lifecycle.

Multi-Cloud
Proprietary
Cloud Service Only
GCPBucketBrute

GCPBucketBrute

Penetration Testing Tools

A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.

GCP
Open Source
Self Hosted Only
Spectral

Spectral

DevSecOps & Pipeline Security

A DevSecOps tool that integrates security into the software development lifecycle, focusing on secret protection and code security.

Multi-Cloud
Proprietary
Cloud Service Only