Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
Switch branches/tags
Nothing to show
Clone or download
shivankarmadaan version 3 opinel-3.3.1
Latest commit 9c6695b Aug 11, 2018

Cloud Security Suite (cs-suite) - Version 3.0

Pre-requisites for Manual setup

  • OS - MacOS or Linux
  • Python 2.7
  • pip
  • git
  • gcc (for sshpass installation (OS Audit). Not a mandatory pre-requisite)
  • AWS Audit - AWS ReadOnly Keys
  • GCP Audit - gcloud setup
  • Azure Audit - Azure user read-only access


git clone
cd cs-suite/
sudo python

Note - Generate a set of ReadOnly AWS keyswhich the tool will ask to finish the installation process. For GCP, setup google cloud SDK.

Running cs-suite

To run AWS Audit - python -env aws
To run GCP Audit - python -env gcp -pId <project_name>
To run Azure Audit - python -env azure
  • The final report will be available in reports directory

  • The final AWS Audit report looks like below:

AWS Audit report

  • The final GCP Audit report looks like below:

GCP Audit report

Docker Setup

  • Create a local directory aws with credentials and config files

  • The config file looks like below

$ cat aws/config

output = json
region = us-east-1
  • The credentials file looks like below
$ cat aws/credentials

aws_access_key_id = XXXXXXXXXXXXXXX

Note: This tool requires arn:aws:iam::aws:policy/ReadOnlyAccess IAM policy

  • Then run the follwing docker command to start
docker run -v `pwd`/aws:/root/.aws -v `pwd`/reports:/app/reports securityftw/cs-suite


docker run -v `pwd`/aws:/root/.aws -v `pwd`/reports:/app/reports securityftw/cs-suite -env aws

Virtual Environment installation

(So you don't mess with the already installed python libraries)

  • pip install virtualenvwrapper
  • add it to the respective rc file of your shell (bashrc/zshrc) (for fish shell users check virtualfish)
  • echo "source /usr/local/bin/" >> ~/.bashrc
  • source the file source ~/.bashrc
  • cd cs-suite/
  • mkvirtualenv cssuite
  • workon cssuite
  • pip install -r requirements-virtual.txt
  • aws configure

Once installation is done, the tool will ask you for the AWS keys and region. These two are mandatory for the tool to work.