Defending cloud Infrastructures with Cloud Security Suite

By Shivankar Madaan on 27 Sep 2018 @ Rootcon
๐Ÿ“Š Presentation ๐Ÿ’ป Source Code ๐Ÿ“น Video ๐Ÿ”— Link
#aws #secure-coding #web-application-security #penetration-testing #blueteam
Focus Areas: Security Operations & Defense , Application Security , Cloud Security , DevSecOps
This talk covers following tools where the speaker has contributed or authored
CLOUD SECURITY SUITE

Presentation Material

Abstract

Nowadays, cloud infrastructure is pretty much the de-facto service used by large/small companies. Most of the major organizations have entirely moved to cloud. With more and more companies moving to cloud, the security of cloud becomes a major concern. While AWS, GCP & Azure provide you protection with traditional security methodologies and have a neat structure for authorization/configuration, their security is as robust as the person in-charge of creating/assigning these configuration policies. As we all know, human error is inevitable and any such human mistake could lead to catastrophic damage to the environment.

Few vulnerable scenarios:

CS Suite is a one stop tool for auditing the security posture of the AWS/GCP/Azure infrastructures and does OS audits as well. CS Suite leverages current open source tools capabilities and has custom checks added into one tool to rule them all.

Cloud Security Suite is an open source which adheres to GPL V3 (GNU General Public License v3.0). This paper is written for the release of the version 3.0 of the tool.

The major features include: