SCOUTSUITE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Multi-cloud security auditing tool by NCC Group. Generates interactive HTML reports for AWS, Azure, GCP, Oracle Cloud, and Alibaba.
INSTALLATION#
pip install scoutsuite # Or: pipx install scoutsuite # From source git clone https://github.com/nccgroup/ScoutSuite cd ScoutSuite && pip install -r requirements.txt
BASIC USAGE#
# AWS (default credentials) scout aws # Azure scout azure --cli # Azure CLI auth scout azure --service-principal # Service principal # GCP scout gcp --user-account # User account scout gcp --service-account /path/to/key.json
AWS SCANNING#
# Full scan scout aws # Specific profile scout aws --profile production # Specific regions scout aws --regions us-east-1 eu-west-1 # Specific services scout aws --services iam s3 ec2 rds # With role assumption scout aws --profile prod --role-arn arn:aws:iam::123456789012:role/AuditRole # Exclude services scout aws --skip iam # Max threads scout aws --max-workers 10
AZURE SCANNING#
# CLI authentication scout azure --cli # Service principal export AZURE_CLIENT_ID=xxx export AZURE_CLIENT_SECRET=xxx export AZURE_TENANT_ID=xxx scout azure --service-principal # Managed identity scout azure --msi # Specific subscription scout azure --cli --subscriptions SUB_ID_1 SUB_ID_2 # Specific services scout azure --cli --services storageaccounts keyvaults
GCP SCANNING#
# User account (browser auth) scout gcp --user-account # Service account scout gcp --service-account /path/to/key.json # Specific project scout gcp --user-account --project-id my-project # All projects scout gcp --user-account --all-projects
OUTPUT#
# Default: generates HTML report in scoutsuite-report/ directory # Open: scoutsuite-report/report.html in browser # The HTML report includes: # Dashboard — overview with risk scores # Service tabs — findings per service # Rules — individual check results # Severity — color-coded (danger, warning, info) # Custom output directory scout aws --report-dir /path/to/output/ # Report name scout aws --report-name prod-audit # No browser auto-open scout aws --no-browser # JSON results # Raw JSON is always saved alongside HTML report # Located in: scoutsuite-report/scoutsuite-results/
RULE CATEGORIES#
# AWS services audited: IAM, S3, EC2, VPC, RDS, Lambda, CloudTrail, CloudWatch, CloudFormation, SQS, SNS, SES, Route53, ELB/ALB, EFS, ElastiCache, EMR, Redshift, DynamoDB, KMS, Config, GuardDuty # Azure services audited: AAD, App Service, Key Vault, Storage, SQL, Network, Virtual Machines, Monitor, Security Center # GCP services audited: IAM, Compute, Storage, SQL, KMS, Logging, Networking, Kubernetes Engine
TIPS#
- HTML report is interactive and self-contained - Share HTML reports with stakeholders directly - Dashboard gives quick risk overview - Filter by severity in the web report - Combine with Prowler for comprehensive coverage - ScoutSuite excels at visual reporting - Prowler has more compliance frameworks - Use --max-workers for faster scans - Service account with read-only permissions is sufficient - Reports can be large; use --services to focus