_____ _ _ _____ _ _
/ ____| | | |/ ____| | | (_)
| | | | ___ _ _ __| | (___ ___ _ __ | |_ _ ___ __
| | | |/ _ \| | | |/ _` |\___ \ / _ \ '_ \| __| | \ \/ /
| |____| | (_) | |_| | (_| |____) | __/ | | | |_| | > <
\_____|_|\___/ \__,_|\__,_|_____/ \___|_| |_|\__|_|_/_/\_\
v2.0.0
Multi-Cloud IAM Attack-Path Analyzer
Open-source CLI that scans GCP, AWS, Azure, Kubernetes, and Terraform for privilege-escalation risks. 40 detection rules · Blast radius · MITRE ATT&CK · Cross-cloud chains · CI/CD ready. The free alternative to Wiz and Orca.
| Target | Rules | Live Scan | Blast Radius | Dashboard | |
|---|---|---|---|---|---|
| ☁️ GCP IAM | 5 | ✅ gcloud | ✅ | ✅ | ✅ |
| 🟡 AWS IAM | 7 | ✅ boto3 + LocalStack | ✅ | ✅ | ✅ |
| 🔷 Azure RBAC | 5 | ✅ az CLI | ✅ | ✅ | ✅ |
| 🔷 Azure AD / Entra ID | 6 | ✅ az CLI | — | ✅ | ✅ |
| 🏗️ Terraform IaC + State | 11 | — | — | — | — |
| ☸️ Kubernetes RBAC | 6 | — | — | — | — |
| 🌐 Cross-Cloud Chains | industry-first | — | — | — | ✅ JSON |
| 🖥️ Local Web Dashboard | — | — | — | ✅ Flask serve |
— |
| Total | 40 rules |
pip install cloudsentrixIf you get externally-managed-environment error on Kali/Debian:
pip install cloudsentrix --break-system-packagesOr use virtual environment (recommended):
python3 -m venv venv
source venv/bin/activate
pip install cloudsentrix
cloudsentrix --versionOr use pipx:
pipx install cloudsentrixpip install cloudsentrix
cloudsentrix --versionOr virtual environment on Windows:
python -m venv venv
venv\Scripts\activate
pip install cloudsentrix
cloudsentrix --versiongit clone https://github.com/Talha-Imran-cloud/cloudsentrix.git
cd cloudsentrix
pip install -e .
cloudsentrix --version# GCP
gcloud projects get-iam-policy YOUR_PROJECT_ID --format=json > gcp_iam.json
# AWS
aws iam get-account-authorization-details --output json > aws_iam.json
# Azure RBAC
az role assignment list --all --output json > azure_rbac.json
# Azure AD
az ad app list --all --output json > azure_ad.json
# Kubernetes
kubectl get clusterroles,clusterrolebindings,roles,rolebindings -o json > k8s_rbac.json# GCP
gcloud projects get-iam-policy YOUR_PROJECT_ID --format=json > gcp_iam.json
# AWS
aws iam get-account-authorization-details --output json > aws_iam.json
# Azure RBAC
az role assignment list --all --output json > azure_rbac.jsonImportant: On Windows PowerShell, use single-line commands. Multi-line
\does not work. All examples below work on both Linux and Windows.
Linux / macOS:
cloudsentrix scan --file gcp_iam.json
cloudsentrix scan --file aws_iam.json --cloud aws
cloudsentrix scan --file azure_rbac.json --cloud azure
cloudsentrix scan --file azure_ad.json --cloud azure-ad
cloudsentrix scan --file gcp_iam.json --severity critical
cloudsentrix scan --file aws_iam.json --cloud aws --notify slackWindows:
cloudsentrix scan --file gcp_iam.json
cloudsentrix scan --file aws_iam.json --cloud aws
cloudsentrix scan --file azure_rbac.json --cloud azure
cloudsentrix scan --file gcp_iam.json --severity criticalcloudsentrix cross-cloud --aws aws_iam.json --azure azure_rbac.json
cloudsentrix cross-cloud --gcp gcp_iam.json --aws aws_iam.json --azure azure_rbac.json
cloudsentrix cross-cloud --aws aws_iam.json --azure azure_rbac.json --output chains.json# Scan .tf files
cloudsentrix terraform --path main.tf
cloudsentrix terraform --path /path/to/terraform/
# Scan .tfstate for leaked secrets
cloudsentrix terraform --path terraform.tfstate
cloudsentrix terraform --path terraform.tfstate --output secrets.jsoncloudsentrix k8s --path k8s_rbac.json
cloudsentrix k8s --path /path/to/manifests/
cloudsentrix k8s --path k8s_rbac.json --output findings.jsonRequires Flask:
pip install flask
Start an interactive browser-based security dashboard running locally at http://127.0.0.1:5000
Linux / macOS:
# Install Flask (one-time)
pip install flask
# Start the local dashboard
cloudsentrix serve
# Custom port
cloudsentrix serve --port 8080
# Open automatically in browser
cloudsentrix serve --openWindows (PowerShell):
# Install Flask (one-time)
pip install flask
# Start the local dashboard
cloudsentrix serve
# Custom port
cloudsentrix serve --port 8080Dashboard features:
- 🖥️ Drop your IAM file directly in the browser (GCP, AWS, Azure, Azure AD)
- 📊 Live security score with animated ring chart
- 🔴 Severity breakdown — CRITICAL / HIGH / MEDIUM findings
- ☁️ Cloud coverage map
- 🔍 Filterable findings table — filter by cloud or severity
- 🔒 Runs entirely on
localhost— no data leaves your machine - 🆓 Competes with Prowler's paid dashboard tier — at zero cost
Linux / macOS:
cloudsentrix dashboard --gcp gcp_iam.json --aws aws_iam.json --azure azure_rbac.json --output dashboard.html
cloudsentrix dashboard --gcp gcp_iam.json --aws aws_iam.json --output dashboard.html
# Open
xdg-open dashboard.htmlWindows:
cloudsentrix dashboard --gcp gcp_iam.json --aws aws_iam.json --azure azure_rbac.json --output dashboard.html
# Open
start dashboard.htmlcloudsentrix report-multi --gcp gcp_iam.json --aws aws_iam.json --azure azure_rbac.json --output report.pdf
cloudsentrix report-multi --gcp gcp_iam.json --aws aws_iam.json --output report.pdfcloudsentrix report --file gcp_iam.json --output report.pdf --no-ai
cloudsentrix report --file aws_iam.json --cloud aws --output aws_report.pdf --no-ai
cloudsentrix report --file azure_rbac.json --cloud azure --output azure_report.pdf --no-ai# GCP (requires gcloud CLI)
cloudsentrix live-scan --project my-gcp-project-id
cloudsentrix live-scan --project my-gcp-project-id --save policy.json
# AWS (requires: pip install boto3)
cloudsentrix live-scan --cloud aws
cloudsentrix live-scan --cloud aws --profile my-profile --region us-east-1
cloudsentrix live-scan --cloud aws --save aws_policy.json
# AWS LocalStack (no real account needed)
cloudsentrix live-scan --cloud aws --endpoint http://localhost:4566
# Azure (requires az login)
cloudsentrix live-scan --cloud azure
cloudsentrix live-scan --cloud azure --subscription my-subscription-id# HTML dashboard
cloudsentrix export --file gcp_iam.json --output dashboard.html
cloudsentrix export --file aws_iam.json --cloud aws --output aws_dashboard.html
cloudsentrix export --file azure_rbac.json --cloud azure --output azure_dashboard.html
# JSON
cloudsentrix export --file gcp_iam.json --output report.json
cloudsentrix export --file aws_iam.json --cloud aws --output aws_report.json
# CSV
cloudsentrix export --file gcp_iam.json --output report.csv
# SARIF (GitHub Code Scanning)
cloudsentrix export --file gcp_iam.json --output results.sarif
cloudsentrix export --file aws_iam.json --cloud aws --output aws_results.sarifcloudsentrix score --file gcp_iam.json
cloudsentrix score --file aws_iam.json --cloud aws
cloudsentrix score --file azure_rbac.json --cloud azure --json
cloudsentrix score --file gcp_iam.json --min-score 70cloudsentrix validate --file gcp_iam.json
cloudsentrix validate --file aws_iam.json --cloud aws
cloudsentrix validate --file azure_rbac.json --cloud azure
cloudsentrix validate --file azure_ad.json --cloud azure-adcloudsentrix blast-radius --file gcp_iam.json --principal admin@company.comcloudsentrix principal-path --file gcp_iam.json --source intern@company.com --target sa@my-project.iam.gserviceaccount.comcloudsentrix mitre-map --file gcp_iam.jsoncloudsentrix remediate --file gcp_iam.json
cloudsentrix remediate --file gcp_iam.json --severity criticalcloudsentrix compare --old january.json --new february.jsoncloudsentrix watch --path gcp_iam.json
cloudsentrix watch --path azure_rbac.json --cloud azure --interval 5cloudsentrix list-principals --file gcp_iam.json
cloudsentrix list-principals --file aws_iam.json --cloud aws
cloudsentrix list-principals --file azure_rbac.json --cloud azurecloudsentrix rules
# GCP(5) + AWS(7) + Azure RBAC(5) + Azure AD(6) + Terraform(11) + K8s(6) = 40 rulesexport CLOUDSENTRIX_SLACK_WEBHOOK="https://hooks.slack.com/services/YOUR/WEBHOOK"
cloudsentrix scan --file gcp_iam.json --notify slack
export CLOUDSENTRIX_TEAMS_WEBHOOK="https://your-org.webhook.office.com/..."
cloudsentrix scan --file gcp_iam.json --notify teams
# Direct URL
cloudsentrix scan --file gcp_iam.json --notify slack --webhook https://hooks.slack.com/services/YOUR/WEBHOOK$env:CLOUDSENTRIX_SLACK_WEBHOOK = "https://hooks.slack.com/services/YOUR/WEBHOOK"
cloudsentrix scan --file gcp_iam.json --notify slack
$env:CLOUDSENTRIX_TEAMS_WEBHOOK = "https://your-org.webhook.office.com/..."
cloudsentrix scan --file gcp_iam.json --notify teams- name: Install CloudSentrix
run: pip install cloudsentrix
- name: Scan GCP IAM
run: cloudsentrix scan --file gcp_iam.json --severity high
- name: Generate SARIF
run: cloudsentrix export --file gcp_iam.json --output results.sarif
- name: Upload to GitHub Security
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: results.sarif
- name: Generate Dashboard
run: cloudsentrix dashboard --gcp gcp_iam.json --aws aws_iam.json --azure azure_rbac.json --output dashboard.html
- name: Upload Dashboard
uses: actions/upload-artifact@v4
with:
name: security-dashboard
path: dashboard.htmlcloudsentrix-scan:
image: python:3.11
script:
- pip install cloudsentrix
- cloudsentrix scan --file gcp_iam.json --cloud gcp
allow_failure: falsestage('Security Scan') {
steps {
sh 'pip install cloudsentrix'
sh 'cloudsentrix scan --file gcp_iam.json --cloud gcp'
}
}pip install localstack awscli-local
localstack start
awslocal iam create-user --user-name test-admin
awslocal iam attach-user-policy --user-name test-admin --policy-arn arn:aws:iam::aws:policy/AdministratorAccess
cloudsentrix live-scan --cloud aws --endpoint http://localhost:4566export GEMINI_API_KEY="your_api_key_here"
cloudsentrix report --file gcp_iam.json --output report.pdf$env:GEMINI_API_KEY = "your_api_key_here"
cloudsentrix report --file gcp_iam.json --output report.pdfGet free API key from Google AI Studio
| Code | Meaning |
|---|---|
0 |
No CRITICAL findings |
1 |
CRITICAL findings — fail the pipeline |
2 |
Command error |
| Rule | Title | Severity | MITRE |
|---|---|---|---|
| GCP-001 | Publicly Accessible Role Binding | CRITICAL | T1078.004 |
| GCP-002 | Service Account Token Creator | CRITICAL | T1098.001 |
| GCP-003 | Service Account Key Admin | CRITICAL | T1098.001 |
| GCP-004 | IAM Policy Administrator | CRITICAL | T1098.003 |
| GCP-005 | Service Account Impersonation via Resource Attach | HIGH | T1548.005 |
| Rule | Title | Severity | MITRE |
|---|---|---|---|
| AWS-001 | Administrator Access — Full AWS Control | CRITICAL | T1078.004 |
| AWS-002 | IAM PassRole — Privilege Escalation via Service | CRITICAL | T1098.003 |
| AWS-003 | IAM Policy Manipulation — Self-Escalation Path | CRITICAL | T1098.003 |
| AWS-004 | Publicly Assumable Role — Trust Policy Allows Anyone | CRITICAL | T1078.004 |
| AWS-005 | Access Key Creation — Long-Lived Credential Backdoor | CRITICAL | T1098.001 |
| AWS-006 | Backdoor IAM User Creation | CRITICAL | T1136.003 |
| AWS-007 | IAMFullAccess — Complete IAM Control | CRITICAL | T1098.003 |
| Rule | Title | Severity | MITRE |
|---|---|---|---|
| AZ-001 | Owner / Contributor at Broad Scope | CRITICAL | T1078.004 |
| AZ-002 | Service Principal with High-Privilege Role | CRITICAL | T1098.001 |
| AZ-003 | Guest User with Elevated Role | HIGH | T1078.006 |
| AZ-004 | Over-permissive Role Scope | HIGH | T1548.005 |
| AZ-005 | Custom Role with Dangerous Permissions | HIGH | T1098.003 |
| Rule | Title | Severity | MITRE |
|---|---|---|---|
| AZAD-001 | Dangerous OAuth Permission | CRITICAL | T1528 |
| AZAD-002 | Orphaned App Registration | HIGH | T1098.001 |
| AZAD-003 | Multi-Tenant App with Broad Permissions | CRITICAL | T1199 |
| AZAD-004 | Expired App Credentials | MEDIUM | T1552.001 |
| AZAD-005 | App Credential With No Expiry | HIGH | T1528 |
| AZAD-006 | Service Principal with High-Privilege App Roles | CRITICAL | T1098.003 |
| Rule | Title | Severity | MITRE |
|---|---|---|---|
| TF-001 | AWS IAM Wildcard Policy (Action:* Resource:*) | CRITICAL | T1078.004 |
| TF-002 | AWS IAM Role Public Trust Policy (Principal:*) | CRITICAL | T1078.004 |
| TF-003 | AWS AdministratorAccess Policy Attached | CRITICAL | T1078.004 |
| TF-004 | GCP Public IAM Binding (allUsers) | CRITICAL | T1078.004 |
| TF-005 | GCP Owner/Editor Role Binding | HIGH | T1098.003 |
| TF-006 | Azure Owner Role Assignment | CRITICAL | T1078.004 |
| TF-007 | Hardcoded Secrets / Access Keys | CRITICAL | T1552.001 |
| TF-008 | AWS IAM Policy Uses NotAction | HIGH | T1078.004 |
| TF-009 | AWS IAM Inline Policy on User | MEDIUM | T1078.004 |
| TF-010 | Sensitive Policy Missing MFA Condition | MEDIUM | T1078.004 |
| TFS-001 | Secret Leaked in Terraform State File | CRITICAL | T1552.001 |
| Rule | Title | Severity | MITRE |
|---|---|---|---|
| K8S-001 | ClusterRoleBinding to cluster-admin | CRITICAL | T1078.001 |
| K8S-002 | Wildcard Permissions in Role | CRITICAL | T1078.001 |
| K8S-003 | Role Can Read Kubernetes Secrets | HIGH | T1552.007 |
| K8S-004 | Default ServiceAccount Bound to Privileged Role | HIGH | T1078.001 |
| K8S-005 | Anonymous / Unauthenticated Access Granted | CRITICAL | T1078.001 |
| K8S-006 | Role Allows Pod Exec/Attach | HIGH | T1609 |
pip install -e ".[dev]"
pytest tests/ -vcloudsentrix/
├── src/
│ ├── cloudsentrix/ # Main package
│ │ ├── __init__.py
│ │ ├── _entry.py # pip install entry point
│ │ ├── cli.py # CLI (19 commands)
│ │ ├── parser.py # GCP parser
│ │ ├── graph.py # GCP graph
│ │ ├── detection.py # GCP rules (5)
│ │ ├── risk_score.py # Scoring engine
│ │ ├── blast_radius.py # GCP blast radius
│ │ ├── watch_handler.py # File watcher
│ │ ├── live_scanner.py # Live GCP scanner
│ │ ├── pdf_report.py # Single PDF
│ │ ├── ai_summary.py # Gemini AI
│ │ ├── aws_parser.py # AWS parser
│ │ ├── aws_graph.py # AWS graph
│ │ ├── aws_detection.py # AWS rules (7)
│ │ ├── aws_blast_radius.py # AWS blast radius
│ │ ├── aws_live_scanner.py # Live AWS scanner
│ │ ├── azure_parser.py # Azure RBAC parser
│ │ ├── azure_detection.py # Azure RBAC rules (5)
│ │ ├── azure_risk_score.py # Azure scoring
│ │ ├── azure_blast_radius.py # Azure blast radius
│ │ ├── azure_exporter.py # Azure exporter
│ │ ├── azure_live_scanner.py # Live Azure scanner
│ │ ├── azure_ad_parser.py # Azure AD parser
│ │ ├── azure_ad_detection.py # Azure AD rules (6)
│ │ ├── terraform_scanner.py # Terraform rules (11)
│ │ ├── k8s_scanner.py # K8s RBAC rules (6)
│ │ ├── cross_cloud_detector.py # Cross-cloud chains
│ │ ├── multi_dashboard.py # Multi-cloud dashboard
│ │ ├── multi_pdf_report.py # Multi-cloud PDF
│ │ ├── web_server.py # Local Web Dashboard (Flask) — NEW
│ │ └── notifier.py # Slack/Teams alerts
├── ci-templates/
│ ├── github-actions-gcp.yml
│ ├── github-actions-aws.yml
│ ├── github-actions-multi-cloud.yml
│ ├── gitlab-ci.yml
│ └── jenkins-pipeline.groovy
├── tests/
├── sample_data/
│ ├── sample_gcp_iam.json
│ ├── sample_aws_iam.json
│ ├── sample_azure_rbac.json
│ ├── sample_azure_ad.json
│ ├── sample_k8s_rbac.json
│ ├── sample_terraform.tfstate
│ └── sample_terraform/main.tf
├── .github/workflows/ci.yml
├── .github/workflows/publish.yml
├── pyproject.toml
└── README.md
| Feature | Status |
|---|---|
| GCP IAM — 5 rules, blast radius, live scan | ✅ Shipped |
| AWS IAM — 7 rules, blast radius, live scan, LocalStack | ✅ Shipped |
| Azure RBAC — 5 rules, blast radius, live scan | ✅ Shipped |
| Azure AD / Entra ID — 6 rules | ✅ Shipped |
| Terraform IaC + State Scanner — 11 rules | ✅ Shipped |
| Kubernetes RBAC Scanner — 6 rules | ✅ Shipped |
| Cross-Cloud Attack Chain Detection | ✅ Shipped |
| Multi-Cloud Dashboard + PDF | ✅ Shipped |
| Slack / Teams Alerts | ✅ Shipped |
| CI/CD Templates | ✅ Shipped |
| Gemini AI Summaries | ✅ Shipped |
Local Web Dashboard (Flask) — cloudsentrix serve |
✅ Shipped |
MIT — free to use, modify, and distribute.