Skip to content
Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.
Python Dart HTML Shell CSS JavaScript Other
Branch: develop
Clone or download
Pull request Compare This branch is 2 commits behind Netflix:develop.
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
dart
data
docker
docs
env-config
env_tests
migrations
nginx
scripts
security_monkey
supervisor
.coveragerc
.dockerignore
.gitignore
.travis.yml
.venv
AUTHORS
Dockerfile
LICENSE
OSSMETADATA
README.md
config-default.py
docker-compose.init.yml
docker-compose.shell.yml
docker-compose.yml
requirements.txt
secmonkey.env
setup.py

README.md

NOTE: Security Monkey is in maintenance mode and will be end-of-life in 2020.

Security Monkey

Security Monkey Logo 2017

Security Monkey monitors your AWS and GCP accounts for policy changes and alerts on insecure configurations. Support is available for OpenStack public and private clouds. Security Monkey can also watch and monitor your GitHub organizations, teams, and repositories.

It provides a single UI to browse and search through all of your accounts, regions, and cloud services. The monkey remembers previous states and can show you exactly what changed, and when.

Security Monkey can be extended with custom account types, custom watchers, custom auditors, and custom alerters.

It works on CPython 2.7. It is known to work on Ubuntu Linux and OS X.

Gitter chat

Develop Branch Master Branch
Build Status Build Status
Coverage Status Coverage Status

Special Note:

Netflix's support for Security Monkey has been reduced for minor bug fixes only. That being said, we are happy to accept and merge pull-requests that fix bugs and add new features as appropriate.

🚨⚠️🥁🎺 PLEASE READ: BREAKING CHANGES FOR 1.0 🎺🥁⚠️🚨

If you are upgrading to 1.0 for the first time, please review the Quickstart and the Autostarting documents as there is a new deployment pattern for Security Monkey. Also, new IAM permissions have been added.

Project resources

Instance Diagram

The components that make up Security Monkey are as follows (not AWS specific): diagram

Access Diagram

Security Monkey accesses accounts to scan via credentials it is provided ("Role Assumption" where available). diagram

You can’t perform that action at this time.