✓ Copied!
Open Source · MIT License · pip install cloudsentrix

Multi-Cloud IAM Attack-Path Analyzer

Cloud
Sentrix

Open-source CLI that scans GCP, AWS, and Azure for privilege-escalation risks — 23 detection rules, blast radius analysis, MITRE ATT&CK mapping, and CI/CD integration. The free alternative to Wiz and Orca.

View on GitHub
☁️ GCP — 5 rules
🟡 AWS — 7 rules
🔷 Azure RBAC — 5 rules
🔷 Azure AD — 6 rules
0Detection Rules
0Cloud Platforms
0Tests Passing
0Paid APIs Required

Capabilities

Security coverage across
every cloud. At zero cost.

One CLI tool that replaces enterprise cloud security scanners — offline, open-source, CI/CD-native, no account required.

01

23 Detection Rules

GCP, AWS, Azure RBAC, and Azure AD — all rules mapped to MITRE ATT&CK Cloud Matrix with exact technique IDs and auto-generated fix commands.

02

Blast Radius Analysis

Calculates how far an attacker can move laterally if one account is compromised — across GCP, AWS, and Azure simultaneously.

03

Cross-Cloud Attack Chains

Detects attack paths that span cloud boundaries — AWS IAM → Azure AD federation → GCP impersonation. Industry-first detection capability.

04

Terraform State Scanning

Scans .tfstate files for leaked credentials, exposed secrets, and misconfigured IaC before they reach production.

05

CI/CD Native Integration

GitHub Actions, GitLab CI, and Jenkins templates included. Exit code 1 on CRITICAL findings — pipeline fails automatically with zero config.

06

Multi-Format Exports

HTML dashboards, PDF reports with AI summaries, SARIF for GitHub Security tab, JSON and CSV — one scan, every output format.

Live Demo

Watch a scan
surface threats.

cloudsentrix — bash

Security Score

0

42

out of 100

Poor — Act Now

Findings by Severity

Critical
6
High
4
Medium
2

Cloud Coverage

☁️ GCP
🟡 AWS
🔷 Azure
🔷 Azure AD

Detection Engine

23 rules. 4 clouds.
Every attack vector.

Rule IDTitleSeverityMITRE
GCP-001Publicly Accessible Role BindingCRITICALT1078.004
GCP-002Service Account Token CreatorCRITICALT1098.001
GCP-003Service Account Key AdminCRITICALT1098.001
GCP-004IAM Policy AdministratorCRITICALT1098.003
GCP-005Service Account Impersonation via Resource AttachHIGHT1548.005
Rule IDTitleSeverityMITRE
AWS-001Administrator Access — Full AWS ControlCRITICALT1078.004
AWS-002IAM PassRole — Privilege Escalation via ServiceCRITICALT1098.003
AWS-003IAM Policy Manipulation — Self-Escalation PathCRITICALT1098.003
AWS-004Publicly Assumable Role — Trust Policy Allows AnyoneCRITICALT1078.004
AWS-005Access Key Creation — Long-Lived Credential BackdoorCRITICALT1098.001
AWS-006Backdoor IAM User CreationCRITICALT1136.003
AWS-007IAMFullAccess — Complete IAM ControlCRITICALT1098.003
Rule IDTitleSeverityMITRE
AZ-001Owner / Contributor at Broad ScopeCRITICALT1078.004
AZ-002Service Principal with High-Privilege RoleCRITICALT1098.001
AZ-003Guest User with Elevated RoleHIGHT1078.006
AZ-004Over-permissive Role ScopeHIGHT1548.005
AZ-005Custom Role with Dangerous PermissionsHIGHT1098.003
Rule IDTitleSeverityMITRE
AZAD-001Dangerous OAuth PermissionCRITICALT1528
AZAD-002Orphaned App RegistrationHIGHT1098.001
AZAD-003Multi-Tenant App with Broad PermissionsCRITICALT1199
AZAD-004Expired App CredentialsMEDIUMT1552.001
AZAD-005App Credential With No ExpiryHIGHT1528
AZAD-006Service Principal with High-Privilege App RolesCRITICALT1098.003

Comparison

Free outperforms paid.
Every time.

Features that cost thousands per month on commercial platforms — available in CloudSentrix at zero cost.

Feature CloudSentrix WizOrcaProwler
Free & Open Source
Multi-Cloud (GCP + AWS + Azure)
Blast Radius Analysis
Cross-Cloud Attack Chain Detection
MITRE ATT&CK MappingPartialPartial
Terraform State ScanningPaidPaid
CI/CD Native (exit codes + templates)PaidPaid
SARIF / GitHub Security TabPartial
Slack / Teams AlertsPaidPaid

Get Started

One command.
Scanning in 60 seconds.

No account. No API key. No credit card. Install and start finding risks in your cloud environment immediately.

# Install CloudSentrix
$ pip install cloudsentrix
 
# Verify
$ cloudsentrix --version
 
# Run your first scan
$ cloudsentrix scan --file sample_data/sample_gcp_iam.json
$ python3 -m venv venv
$ source venv/bin/activate
$ pip install cloudsentrix
$ cloudsentrix --version
# Kali Linux / Debian
$ pip install cloudsentrix --break-system-packages
$ cloudsentrix --version
$ git clone https://github.com/Talha-Imran-cloud/cloudsentrix.git
$ cd cloudsentrix && pip install -e .
$ cloudsentrix --version

Contact

Get in touch.

Have questions about CloudSentrix, want to contribute, or need help with your cloud security setup? Reach out directly.

LinkedIn

Talha Imran

Email

talhaimran20008@gmail.com

Send a Message

Message will open in your email client.