FestIn - Credentialless discovery and monitoring of exposed S3-compatible cloud storage from domains, DNS and web crawling.
-
Updated
Sep 8, 2026 - Python
FestIn - Credentialless discovery and monitoring of exposed S3-compatible cloud storage from domains, DNS and web crawling.
Professional AWS pentest tool: IAM privilege escalation, S3 exploits, compute enumeration, detailed audit reports
Learn AWS Security by Example
A CLI utility to scan S3 buckets permissions
A micro InSpec baseline to check for insecure or public s3 buckets in your VPC
S3Insights is a platform for efficiently deriving security insights about S3 data through metadata analysis
DEMO: A kitchen-terraform based example of building and validating AWS security settings
Enterprise-grade autonomous DevSecOps and AWS cost optimization engine. Dynamically detects S3/IAM vulnerabilities and generates zero-touch Terraform remediation.
19 Claude SAST prompts for AWS pentest tool security review (IAM, S3, EKS, Secrets, Backdoors)
Example: AWS InSpec profile for validation of AWS infrastructure
Hands-on AWS security lab investigating a simulated cloud breach through CloudTrail log analysis. Traces complete attack chain from compromised IAM credentials through privilege escalation to S3 data exfiltration. Demonstrates forensic analysis, IAM security, and incident response techniques.
Automated cloud-security detection and response framework for adaptive defense across AWS environments.
Python scripts for pre-audit cloud security evidence collection across AWS, GCP, and Azure. SOC 2 and ISO 27001 control mappings. Read-only, open-source
Local-first AWS security auditor CLI that scans S3, EC2, IAM & RDS, maps findings to CIS/SOC2/HIPAA, and generates HTML reports with remediation commands.
Nimbus - AWS Security Assessment MCP Server | 45 Tools | Multi-Region Scanning | TRA Reports | CIS/NIST/PCI-DSS Compliance
AWS Cloud Security Monitoring & Hardening project demonstrating cloud threat detection, incident investigation, automated alerting, and security hardening using CloudTrail, GuardDuty, SNS, Lambda, IAM, EC2, and S3.
Cloud-hosted Betterleaks for GitHub and S3 secret scanning with live vendor-API validation. Apify actor.
Validation-first AWS security assessment toolkit with read-only posture checks, finding normalization, remediation reporting, synthetic validation, and CI-enforced guardrails.
Cloud-Native AWS Security Posture Management using Terraform and Prowler
Serverless security scanning engine for AWS environments. Detects IAM privilege escalation, unauthenticated API exposure, and storage misconfigurations via active abuse simulation — not static checks.
To associate your repository with the s3-security topic, visit your repo's landing page and select "manage topics."