Cloud SecurityActiveOpen source
CloudSentry: AWS Security Watchdog
CloudSentry runs weekly (or on-demand via API Gateway) to audit AWS accounts for security misconfigurations, policy violations, resource waste, and infrastructure drift. It scans IAM, networking, compute, storage, databases, encryption, logging, and DNS across all regions and multiple accounts via STS AssumeRole. Every finding includes a severity-weighted score deduction and a copy-paste remediation command. Results are stored in DynamoDB for week-over-week trending, published as an HTML dashboard on CloudFront, and delivered via styled SES emails and Slack. The entire stack costs under $0.25/month and deploys with a single Terraform command.
Highlights
- ▸Scores infrastructure 0-100 mapped to CIS AWS Foundations Benchmark
- ▸Multi-account, multi-region with copy-paste fix commands for every finding
- ▸Full serverless architecture at ~$0.21/month, one-command deploy and destroy
Tech Stack
AWSLambdaTerraformDynamoDBS3CloudFrontSESSNSAPI GatewayPython