Cloudsplaining

A command-line tool that assesses AWS IAM policies for excessive permissions and security risks.

Compare Cloudsplaining with another product

Read the Cloudsplaining documentation

Alternatives

See all alternatives

About Cloudsplaining

Cloudsplaining scans AWS IAM policies for least-privilege violations and produces a risk-prioritized HTML report. It can assess a policy file or authorization details from one or more AWS accounts.

Findings include risks such as data exfiltration, infrastructure modification, resource exposure and privilege escalation. Account scans require AWS credentials with permission to retrieve IAM authorization details.

Strengths

  • Scans individual policies or account authorization details
  • Groups findings by security risk
  • Produces HTML and JSON output

Limitations

  • Account scans require configured AWS credentials and IAM read permissions

Details

Pricing
FreeFree and open source under the BSD 3-Clause license.
License
BSD-3-Clause
Developer
Salesforce
Platforms
Command line
How it runs
Downloadable app
Best suited for
AWS administrators reviewing IAM permissions for excessive access
Last verified
Added
Provenance
Selected from the Homebrew formula

Report a wrong fact or a dead link on this listing