← All cheat sheets

SCOUTSUITE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Multi-cloud security auditing tool by NCC Group. Generates
interactive HTML reports for AWS, Azure, GCP, Oracle Cloud, and Alibaba.

INSTALLATION#

pip install scoutsuite
# Or: pipx install scoutsuite

# From source
git clone https://github.com/nccgroup/ScoutSuite
cd ScoutSuite && pip install -r requirements.txt

BASIC USAGE#

# AWS (default credentials)
scout aws

# Azure
scout azure --cli                           # Azure CLI auth
scout azure --service-principal             # Service principal

# GCP
scout gcp --user-account                    # User account
scout gcp --service-account /path/to/key.json

AWS SCANNING#

# Full scan
scout aws

# Specific profile
scout aws --profile production

# Specific regions
scout aws --regions us-east-1 eu-west-1

# Specific services
scout aws --services iam s3 ec2 rds

# With role assumption
scout aws --profile prod --role-arn arn:aws:iam::123456789012:role/AuditRole

# Exclude services
scout aws --skip iam

# Max threads
scout aws --max-workers 10

AZURE SCANNING#

# CLI authentication
scout azure --cli

# Service principal
export AZURE_CLIENT_ID=xxx
export AZURE_CLIENT_SECRET=xxx
export AZURE_TENANT_ID=xxx
scout azure --service-principal

# Managed identity
scout azure --msi

# Specific subscription
scout azure --cli --subscriptions SUB_ID_1 SUB_ID_2

# Specific services
scout azure --cli --services storageaccounts keyvaults

GCP SCANNING#

# User account (browser auth)
scout gcp --user-account

# Service account
scout gcp --service-account /path/to/key.json

# Specific project
scout gcp --user-account --project-id my-project

# All projects
scout gcp --user-account --all-projects

OUTPUT#

# Default: generates HTML report in scoutsuite-report/ directory
# Open: scoutsuite-report/report.html in browser

# The HTML report includes:
#   Dashboard — overview with risk scores
#   Service tabs — findings per service
#   Rules — individual check results
#   Severity — color-coded (danger, warning, info)

# Custom output directory
scout aws --report-dir /path/to/output/

# Report name
scout aws --report-name prod-audit

# No browser auto-open
scout aws --no-browser

# JSON results
# Raw JSON is always saved alongside HTML report
# Located in: scoutsuite-report/scoutsuite-results/

RULE CATEGORIES#

# AWS services audited:
  IAM, S3, EC2, VPC, RDS, Lambda, CloudTrail,
  CloudWatch, CloudFormation, SQS, SNS, SES,
  Route53, ELB/ALB, EFS, ElastiCache, EMR,
  Redshift, DynamoDB, KMS, Config, GuardDuty

# Azure services audited:
  AAD, App Service, Key Vault, Storage, SQL,
  Network, Virtual Machines, Monitor, Security Center

# GCP services audited:
  IAM, Compute, Storage, SQL, KMS, Logging,
  Networking, Kubernetes Engine

TIPS#

  - HTML report is interactive and self-contained
  - Share HTML reports with stakeholders directly
  - Dashboard gives quick risk overview
  - Filter by severity in the web report
  - Combine with Prowler for comprehensive coverage
  - ScoutSuite excels at visual reporting
  - Prowler has more compliance frameworks
  - Use --max-workers for faster scans
  - Service account with read-only permissions is sufficient
  - Reports can be large; use --services to focus