<p align="center">
<img src="https://user-images.githubusercontent.com/4206926/49877604-10457580-fe26-11e8-92d7-cd876c4f6454.png" width=350/>
</p>
#
[![Travis](https://travis-ci.org/nccgroup/ScoutSuite.svg?branch=master)](https://travis-ci.org/nccgroup/ScoutSuite)
[![Coverage Status](https://coveralls.io/repos/github/nccgroup/ScoutSuite/badge.svg?branch=master)](https://coveralls.io/github/nccgroup/ScoutSuite?branch=master)
[![CodeCov](https://codecov.io/gh/nccgroup/ScoutSuite/branch/master/graph/badge.svg)](https://codecov.io/gh/nccgroup/ScoutSuite)
[![PyPI version](https://badge.fury.io/py/ScoutSuite.svg)](https://badge.fury.io/py/ScoutSuite)
## Description
Scout Suite is an open source multi-cloud security-auditing tool, which enables security posture assessment of cloud
environments. Using the APIs exposed by cloud providers, Scout Suite gathers configuration data for manual inspection
and highlights risk areas. Rather than going through dozens of pages on the web consoles, Scout Suite presents a clear
view of the attack surface automatically.
Scout Suite is stable and actively maintained, but a number of features and internals may change. As such, please bear
with us as we find time to work on, and improve, the tool. Feel free to report a bug with details (please provide
console output using the `--debug` argument), request a new feature, or send a pull request.
The project team can be contacted at <scoutsuite@nccgroup.com>.
**Note:**
The latest (and final) version of Scout2 can be found in <https://github.com/nccgroup/Scout2/releases> and
<https://pypi.org/project/AWSScout2>. Further work is not planned for Scout2. Fixes will be implemented in Scout Suite.
### Support
The following cloud providers are currently supported/planned:
- Amazon Web Services
- Microsoft Azure (beta)
- Google Cloud Platform
- Alibaba Cloud (early alpha)
- Oracle Cloud Infrastructure (early alpha)
### Installation
Refer to the [wiki](https://github.com/nccgroup/ScoutSuite/wiki/Setup).
## Compliance
### AWS
Use of Scout Suite does not require AWS users to complete and submit the AWS Vulnerability / Penetration Testing
Request Form. Scout Suite only performs API calls to fetch configuration data and identify security gaps, which is not
considered security scanning as it does not impact AWS' network and applications.
### Azure
Use of Scout Suite does not require Azure users to contact Microsoft to begin testing. The only requirement is that
users abide by the Microsoft Cloud Unified Penetration Testing Rules of Engagement.
References:
- https://docs.microsoft.com/en-us/azure/security/azure-security-pen-testing
- https://www.microsoft.com/en-us/msrc/pentest-rules-of-engagement
### Google Cloud Platform
Use of Scout Suite does not require GCP users to contact Google to begin testing. The only requirement is that users
abide by the Cloud Platform Acceptable Use Policy and the Terms of Service and ensure that tests only affect projects
you own (and not other customers' applications).
References:
- https://cloud.google.com/terms/aup
- https://cloud.google.com/terms/
## Usage
The following command will provide the list of available command line options:
$ python scout.py --help
You can also use this to get help on a specific provider:
$ python scout.py PROVIDER --help
For further details, checkout our Wiki pages at <https://github.com/nccgroup/ScoutSuite/wiki>.
After performing a number of API calls, Scout will create a local HTML report and open it in the default browser.
Also note that the command line will try to infer the argument name if possible when receiving partial switch. For
example, this will work and use the selected profile:
$ python scout.py aws --profile PROFILE
### Credentials
Assuming you already have your provider's CLI up and running you should have your credentials already set up and be able to run Scout Suite by using one of the following commands. If that is not the case, please consult the wiki page for the provider desired.
#### [Amazon Web Services](https://github.com/nccgroup/ScoutSuite/wiki/Amazon-Web-Services)
$ python scout.py aws
#### [Azure](https://github.com/nccgroup/ScoutSuite/wiki/Azure)
$ python scout.py azure --cli
#### [Google Cloud Platform](https://github.com/nccgroup/ScoutSuite/wiki/Google-Cloud-Platform)
$ python scout.py gcp --user-account
Additional information can be found in the [wiki](https://github.com/nccgroup/ScoutSuite/wiki).
没有合适的资源?快使用搜索试试~ 我知道了~
温馨提示
资源分类:Python库 所属语言:Python 资源全名:ScoutSuite-5.3.2.tar.gz 资源来源:官方 安装方法:https://lanzao.blog.csdn.net/article/details/101784059
资源详情
资源评论
资源推荐
收起资源包目录
Python库 | ScoutSuite-5.3.2.tar.gz (745个子文件)
setup.cfg 38B
scoutsuite.css 8KB
scoutsuite-dark.css 2KB
scoutsuite-light.css 751B
modal.css 510B
services.ecs.regions.id.instances.html 12KB
report.html 9KB
metadata.html 7KB
services.network.network_interfaces.html 6KB
services.network.security_groups.html 6KB
services.rds.regions.id.instances.html 5KB
services.sqldatabase.servers.html 5KB
services.computeengine.projects.id.zones.id.instances.html 4KB
services.computeengine.projects.id.firewalls.html 4KB
services.s3.buckets.html 4KB
services.network.virtual_networks.id.subnets.html 4KB
services.iam.permissions.html 4KB
services.kms.keyvaults.html 4KB
services.vpc.regions.id.vpcs.html 4KB
services.virtualmachines.instances.html 4KB
dashboard.html 4KB
services.ram.users.html 3KB
services.elb.regions.id.vpcs.id.elbs.html 3KB
services.network.virtual_networks.html 3KB
services.elbv2.regions.id.vpcs.id.lbs.html 3KB
services.rds.regions.id.vpcs.id.instances.html 3KB
services.iam.users.html 3KB
services.objectstorage.buckets.html 3KB
services.vpc.regions.id.vpcs.html 3KB
services.iam.projects.id.service_accounts.html 3KB
services.emr.regions.id.vpcs.id.clusters.html 3KB
services.ec2.regions.id.vpcs.id.instances.html 3KB
services.cloudsql.projects.id.instances.html 3KB
services.s3.bucket_iam_policies.html 3KB
services.cloudtrail.regions.id.trails.html 3KB
services.vpc.regions.id.vpcs.id.network_acls.html 3KB
services.iam.credential_reports.html 3KB
services.iam.password_policy.html 3KB
services.s3.acls.html 3KB
services.redshift.regions.id.vpcs.id.clusters.html 3KB
services.computeengine.projects.id.regions.id.subnetworks.html 3KB
services.kms.projects.id.keyrings.html 3KB
services.sns.regions.id.topics.html 3KB
services.graphrbac.users.html 3KB
services.cloudformation.regions.id.stacks.html 3KB
network_interface.html 3KB
services.cloudstorage.projects.id.buckets.html 3KB
services.storageaccounts.storage_accounts.html 3KB
services.identity.groups.html 3KB
services.actiontrail.trails.html 3KB
services.vpc.regions.id.vpcs.id.subnets.html 3KB
services.ram.password_policy.html 2KB
services.cloudresourcemanager.projects.id.bindings.html 2KB
services.ec2.regions.vpcs.security_groups.rule_list.html 2KB
services.ram.policies.html 2KB
services.kms.regions.id.keys.html 2KB
services.vpc.regions.id.peering_connections.html 2KB
left_menu_for_gcp_region.html 2KB
left_menu_for_gcp_zone.html 2KB
services.ram.groups.html 2KB
services.elb.regions.id.elb_policies.html 2KB
services.iam.roles.html 2KB
services.ec2.regions.id.vpcs.id.security_groups.html 2KB
services.cloudwatch.regions.id.alarms.html 2KB
left_menu_for_vpc.html 2KB
services.ram.security_policy.html 2KB
services.config.regions.html 2KB
services.identity.password_policy.html 2KB
services.rds.regions.id.parameter_groups.html 2KB
resources_details.html 2KB
services.ram.roles.html 2KB
services.computeengine.projects.id.networks.html 2KB
last_run_details.html 2KB
services.securitycenter.security_contacts.html 2KB
services.route53.regions.id.domains.html 2KB
services.identity.users.html 2KB
left_menu_for_project.html 2KB
services.sqs.regions.id.queues.html 2KB
services.identity.policies.html 2KB
left_menu_for_aliyun_region.html 2KB
left_menu_for_region.html 2KB
services.iam.groups.html 2KB
services.redshift.regions.id.vpcs.id.security_groups.html 2KB
services.computeengine.projects.id.snapshots.html 2KB
services.s3.buckets.objects.html 2KB
services.vpc.regions.id.vpcs.id.flow_logs.html 2KB
services.cloudresourcemanager.projects.id.groups.html 1KB
services.rds.regions.id.vpcs.id.snapshots.html 1KB
services.cloudresourcemanager.projects.id.users.html 1KB
services.route53.regions.id.hosted_zones.html 1KB
services.ec2.regions.vpcs.security_groups.resource_list.html 1KB
services.network.watchers.html 1KB
services.stackdriverlogging.projects.id.sinks.html 1KB
services.ses.regions.id.identities.html 1KB
services.ec2.regions.id.snapshots.html 1KB
services.elb.regions.id.vpcs.id.elbs.linked_resources.html 1KB
services.iam.managed_policies.html 1KB
accordion.html 1KB
services.stackdriverlogging.sinks.html 1KB
services.cloudtrail.regions.html 1KB
共 745 条
- 1
- 2
- 3
- 4
- 5
- 6
- 8
挣扎的蓝藻
- 粉丝: 14w+
- 资源: 15万+
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
最新资源
- 简单的minecraft启发程序,使用Python和Pyglet.zip
- 简单的python文本处理,情感分析,词性标注,名词短语提取,翻译等.zip
- 混合储能容量优化配置(钠硫电池、超级电容) 基于emd和vmd容量配置 1、先用vmd进行输入功率分解,通过分解出高频信号和低频信号,混合储能的功率分配,分给钠硫电池、超级电容 2、分解后再求出储能
- 简单的Python版本管理.zip
- 简单而高效的pytorchnative转换器文本生成在1000 LOC的python.zip
- 简短的Python代码片段,满足您的所有开发需求.zip
- 简单的python远程执行和部署.zip
- 剑指 Offer Python Java C 解题代码LeetBook图解算法数据结构配套代码仓.zip
- 将curl命令转换为Python、JavaScript和其他27种语言.zip
- 将Python程序包冻结为独立的可执行文件.zip
- 解决机器学习中不平衡数据集诅咒的Python包.zip
- 将Python应用程序转换为Android APK.zip
- 惊人的QRCode生成器在Python中支持动画gif.zip
- 静态站点生成器支持Markdown和reST语法,由Python提供支持.zip
- 具有复杂过滤支持的FFmpeg的Python绑定.zip
- 基于新算法SSA优化变分模态分解的混合储能功率分配策略 vmd、emd、ssavmd分解风电功率 高频给超级电容、低频给蓄电池 适应值函数由样本墒、聚合代数、Pearson构成创新性比较大 参考基
资源上传下载、课程学习等过程中有任何疑问或建议,欢迎提出宝贵意见哦~我们会及时处理!
点击此处反馈
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功
评论0