gebalamariusz 3 hours ago
That's why I didn't focus on an incredible number of checks, but rather on the correlation between them. Something like a vulnerability based on findings (Public Security Group with port 22 -> IMDSv1 -> IAM Roles on EC2 with high access), which individually might not seem dangerous, but when combined, they create a real opportunity for attackers. Taking a bit of inspiration from other scanners, I've also added an option to automatically fix the issue (of course, this is just a hint on how to do it, but it's always more convenient to get a ready-made Terraform snippet instead of searching for fixes in the documentation).
I still have a lot of ideas for developing this, so I'd like to show you what it looks like now and would love to hear your feedback on whether you think it makes sense or whether tools like Prowler have already completely covered this sector in terms of security. I've recently added CIS 3.0 and SOC 2 compliance reports. This isn't SaaS—it's completely open source with the simplest possible installation. Documentation is available on the repo.
If you have any questions or ideas, I would be extremely grateful for each one.