Schema-driven awesome list of cloud security guardrails powering cloudguardrail.com/tools
-
Updated
May 21, 2026 - JavaScript
Schema-driven awesome list of cloud security guardrails powering cloudguardrail.com/tools
Cloud security audit tools for AI agents — AWS, Azure, GCP misconfiguration detection via MCP. 38 tools, 60+ checks. The agent finds vulns, not you.
Open-source platform for machine identity security — discover, map, and risk-score IAM roles, OIDC federations, and CI/CD tokens across AWS
AWS Cloud Security Posture & Misconfiguration Assessment Engine
Visual IAM attack graph for AWS. Instantly analyze permissions, detect privilege-escalation risks, and audit IAM roles — locally, securely.
The governance-native Agent OS. Cryptographically sealed 10-Law security, tri-model cognitive orchestration, and secure full-stack computer use with immutable CAC accountability.
IAM Policy Analyzer & Fixer
AWS-native Cloud Security Platform for continuous IAM governance, privilege escalation detection, S3/EC2/RDS/EKS exposure scanning, trust policy analysis, access key auditing, security scoring (0–100), and CloudWatch-based security monitoring — built in Go & Terraform.
Hands-on AWS security lab investigating a simulated cloud breach through CloudTrail log analysis. Traces complete attack chain from compromised IAM credentials through privilege escalation to S3 data exfiltration. Demonstrates forensic analysis, IAM security, and incident response techniques.
Python scripts for pre-audit cloud security evidence collection across AWS, GCP, and Azure. SOC 2 and ISO 27001 control mappings. Read-only, open-source
AWS penetration testing guide — IAM privilege escalation, S3, Lambda, EKS, cross-account attacks, privilege escalation paths
Local-first AWS security auditor CLI that scans S3, EC2, IAM & RDS, maps findings to CIS/SOC2/HIPAA, and generates HTML reports with remediation commands.
Python pipeline that ingests CloudTrail-style logs, runs 8 MITRE ATT&CK-mapped detection rules (T1078, T1098, T1110), and surfaces 43 severity-ranked findings in a Streamlit dashboard — replicating CSPM and SOC triage workflows.
Automated cloud-security detection and response framework for adaptive defense across AWS environments.
Event-driven AWS cloud security automation that detects IAM privilege escalation, alerts security teams via SNS, and supports governance-aware remediation using Terraform and Python.
Cloud-native SOAR pipeline: GuardDuty + EventBridge + Lambda auto-remediation | IAM misconfiguration + S3 exfiltration detection | 10 AWS services | MTTR < 30s
Defensive AWS IAM attack-path analysis and privilege-escalation detection tool.
A curated list of cloud security tools for AWS, Azure, GCP, and Kubernetes
Hands-on AWS attack chain and incident response lab demonstrating IAM privilege escalation, STS session abuse, S3 data exposure, CloudTrail investigation, containment, remediation, and security validation using Terraform and AWS security tooling.
Public-safe cloud detection engineering lab with synthetic AWS events, detections-as-code, expected alerts, runbooks, validation, and dashboard.
To associate your repository with the iam-security topic, visit your repo's landing page and select "manage topics."