Open Source Audit Software
Cloud accounts sprawl faster than anyone can track by hand, and a single overly permissive role or public bucket can undo every other control you put in place. The open source tools here let you inspect how your accounts, infrastructure code, and clusters are evaluated for posture and run those checks yourself, so the keys and findings about your environment never leave it for an outside platform.

Prowler
Open-source cloud security platform for automated checks, compliance frameworks, and multi-cloud assessments

Kubescape
Kubernetes security platform spanning IDEs, CI/CD pipelines, and live clusters
kube-bench
Checks whether Kubernetes is deployed according to the CIS Kubernetes Benchmark

Steampipe
Zero-ETL SQL access to APIs and services, with live queries and a single binary

ScoutSuite
Open source multi-cloud security auditing tool for point-in-time posture assessment and offline review

Cartography
Python tool that maps infrastructure assets and relationships into a Neo4j graph database

CloudSploit
Cloud security auditing for AWS, Azure, GCP, Oracle, and GitHub with compliance reporting
KubeLinter
Static analysis for Kubernetes YAML files, Helm charts, and Kustomize manifests

Chamber
CLI for managing secrets in AWS SSM Parameter Store, with audit history and export-import commands