Skip to content

Cloud & Kubernetes Security

Audit cloud accounts, IAM policy, container images, and clusters.

ScoutSuite

venv

Multi-cloud security-posture auditing (AWS/Azure/GCP/…) with an HTML report.

Prowler

venv

AWS/Azure/GCP/K8s CIS-benchmark and best-practice auditing.

Cloudsplaining

venv

Flags risky AWS IAM policies (privilege escalation, wildcard actions).

kube-hunter

venv

Hunts for exploitable weaknesses in a Kubernetes cluster.

Trivy

system

Vulnerability/misconfig scanner for images, filesystems, and IaC.

kube-bench

binary

Checks a cluster against the CIS Kubernetes Benchmark.

whoAMI-scanner

binary NEW

Scans an AWS account for the "whoAMI" AMI name-confusion attack (Datadog).

EKSHolmes

redcloudos NEW

Enumerates AWS EKS clusters (RedCloudOS's own tool). No upstream release exists — built from Go source at ISO build time.

AzureHound

binary NEW

BloodHound-style attack-path data collector for Entra ID/Azure (SpecterOps).

cloudfox

binary NEW

Situational-awareness enumeration for cloud penetration tests (BishopFox).

CloudBrute

binary NEW

Cloud infrastructure/asset enumerator across AWS/Azure/GCP/DigitalOcean/etc.

peirates

binary NEW

Kubernetes penetration-testing tool for privilege escalation inside a cluster.

gitleaks

binary NEW

Scans git history/filesystems for hardcoded secrets and credentials.

Pacu

venv NEW

Rhino Security Labs' AWS exploitation framework — post-compromise enumeration and attack modules.

roadtx

venv NEW

ROADtools' Entra ID/Azure AD token-exchange and authentication toolkit.

Cartography

venv NEW

Lyft's infrastructure asset-graph tool — ingests AWS/Azure/GCP/K8s state into Neo4j for attack-path queries.

PMapper

redcloudos NEW

Evaluates AWS IAM permissions to find privilege-escalation paths (NCC Group original, RedCloudOS fork).

heimdall

redcloudos NEW

AWS attack-path scanner covering privilege escalation across 10+ services.

GCPBucketBrute

redcloudos NEW

Enumerates GCS bucket names and checks/privesc's your access to each.

GCPTokenReuse

redcloudos NEW

Single-script tool that reuses a compromised GCP OAuth token across scopes/services.

gcp_scanner

redcloudos NEW

Comprehensive scanner for exposed/misconfigured Google Cloud resources.

KubiScan

redcloudos NEW

Scans a Kubernetes cluster for risky RBAC roles/bindings and risky pods.

AWeSomeUserFinder

redcloudos NEW

AWS IAM username enumeration and password-spraying tool.

Oh365UserFinder

redcloudos NEW

Office 365 / Entra ID username enumeration tool.

cloud_enum

redcloudos NEW

Multi-cloud OSINT enumeration of public resources across AWS/Azure/GCP.