Multi-Cloud IAM Attack-Path Analyzer
Open-source CLI that scans GCP, AWS, and Azure for privilege-escalation risks — 23 detection rules, blast radius analysis, MITRE ATT&CK mapping, and CI/CD integration. The free alternative to Wiz and Orca.
Capabilities
One CLI tool that replaces enterprise cloud security scanners — offline, open-source, CI/CD-native, no account required.
01
GCP, AWS, Azure RBAC, and Azure AD — all rules mapped to MITRE ATT&CK Cloud Matrix with exact technique IDs and auto-generated fix commands.
02
Calculates how far an attacker can move laterally if one account is compromised — across GCP, AWS, and Azure simultaneously.
03
Detects attack paths that span cloud boundaries — AWS IAM → Azure AD federation → GCP impersonation. Industry-first detection capability.
04
Scans .tfstate files for leaked credentials, exposed secrets, and misconfigured IaC before they reach production.
05
GitHub Actions, GitLab CI, and Jenkins templates included. Exit code 1 on CRITICAL findings — pipeline fails automatically with zero config.
06
HTML dashboards, PDF reports with AI summaries, SARIF for GitHub Security tab, JSON and CSV — one scan, every output format.
Live Demo
Security Score
out of 100
Poor — Act Now
Findings by Severity
Cloud Coverage
Detection Engine
| Rule ID | Title | Severity | MITRE |
|---|---|---|---|
| GCP-001 | Publicly Accessible Role Binding | CRITICAL | T1078.004 |
| GCP-002 | Service Account Token Creator | CRITICAL | T1098.001 |
| GCP-003 | Service Account Key Admin | CRITICAL | T1098.001 |
| GCP-004 | IAM Policy Administrator | CRITICAL | T1098.003 |
| GCP-005 | Service Account Impersonation via Resource Attach | HIGH | T1548.005 |
| Rule ID | Title | Severity | MITRE |
|---|---|---|---|
| AWS-001 | Administrator Access — Full AWS Control | CRITICAL | T1078.004 |
| AWS-002 | IAM PassRole — Privilege Escalation via Service | CRITICAL | T1098.003 |
| AWS-003 | IAM Policy Manipulation — Self-Escalation Path | CRITICAL | T1098.003 |
| AWS-004 | Publicly Assumable Role — Trust Policy Allows Anyone | CRITICAL | T1078.004 |
| AWS-005 | Access Key Creation — Long-Lived Credential Backdoor | CRITICAL | T1098.001 |
| AWS-006 | Backdoor IAM User Creation | CRITICAL | T1136.003 |
| AWS-007 | IAMFullAccess — Complete IAM Control | CRITICAL | T1098.003 |
| Rule ID | Title | Severity | MITRE |
|---|---|---|---|
| AZ-001 | Owner / Contributor at Broad Scope | CRITICAL | T1078.004 |
| AZ-002 | Service Principal with High-Privilege Role | CRITICAL | T1098.001 |
| AZ-003 | Guest User with Elevated Role | HIGH | T1078.006 |
| AZ-004 | Over-permissive Role Scope | HIGH | T1548.005 |
| AZ-005 | Custom Role with Dangerous Permissions | HIGH | T1098.003 |
| Rule ID | Title | Severity | MITRE |
|---|---|---|---|
| AZAD-001 | Dangerous OAuth Permission | CRITICAL | T1528 |
| AZAD-002 | Orphaned App Registration | HIGH | T1098.001 |
| AZAD-003 | Multi-Tenant App with Broad Permissions | CRITICAL | T1199 |
| AZAD-004 | Expired App Credentials | MEDIUM | T1552.001 |
| AZAD-005 | App Credential With No Expiry | HIGH | T1528 |
| AZAD-006 | Service Principal with High-Privilege App Roles | CRITICAL | T1098.003 |
Comparison
Features that cost thousands per month on commercial platforms — available in CloudSentrix at zero cost.
| Feature | CloudSentrix | Wiz | Orca | Prowler |
|---|---|---|---|---|
| Free & Open Source | ✓ | — | — | ✓ |
| Multi-Cloud (GCP + AWS + Azure) | ✓ | ✓ | ✓ | ✓ |
| Blast Radius Analysis | ✓ | ✓ | ✓ | — |
| Cross-Cloud Attack Chain Detection | ✓ | — | — | — |
| MITRE ATT&CK Mapping | ✓ | Partial | Partial | ✓ |
| Terraform State Scanning | ✓ | Paid | Paid | — |
| CI/CD Native (exit codes + templates) | ✓ | Paid | Paid | ✓ |
| SARIF / GitHub Security Tab | ✓ | — | — | Partial |
| Slack / Teams Alerts | ✓ | Paid | Paid | — |
Get Started
No account. No API key. No credit card. Install and start finding risks in your cloud environment immediately.
Contact
Have questions about CloudSentrix, want to contribute, or need help with your cloud security setup? Reach out directly.
Talha Imran
talhaimran20008@gmail.com
Message will open in your email client.