- https://github.com/cloud-custodian/cloud-custodian - CapOne multicloud rules engine.
- https://github.com/Netflix/edda - Edda is a service that polls your AWS resources via AWS APIs and records the results. It allows you to quickly search through your resources and shows you how they have changed over time.
- https://github.com/Netflix/security_monkey - EOL'd. Support AWS, GCP, Github.
- https://github.com/devops-israel/aws-inventory - Client/browser side inventory.
- https://github.com/turbot/steampipe
- https://github.com/cloudquery/cloudquery
- https://github.com/scopely-devops/skew - Skew is a package for identifying and enumerating cloud resources.
- https://github.com/lyft/cartography - Python tool for infra assets and relationships; backed by Neo4j.
- https://github.com/toniblyx/prowler - AWS CIS + extras scanner.
- https://github.com/nccgroup/ScoutSuite
- https://github.com/dowjones/hammer
- https://github.com/prezi/reddalert - AWS risky security change detector built atop EDDA.
- https://docs.chef.io/inspec/
- https://github.com/RhinoSecurityLabs/pacu
- Instacart - S3 - https://github.com/ankane/s3tk
- Salesforce - IAM - https://github.com/salesforce/cloudsplaining
- Duo - IAM linter - https://github.com/duo-labs/parliament/
- Billing ELK - https://github.com/ProTip/aws-elk-billing
- AWS - https://aws.amazon.com/config/
- AWS - https://github.com/awslabs/aws-config-resource-schema
- GCP - https://cloud.google.com/asset-inventory/docs/overview
- https://github.com/fugue/regula - Checks Terraform for AWS, Azure and GCP security and CIS compliance using opa/rego.
- https://github.com/GoogleCloudPlatform/terraformer
- https://github.com/cycloidio/terracognita
- https://github.com/dtan4/terraforming