# jonrau1/ElectricEye

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

Repository: https://github.com/jonrau1/ElectricEye
Canonical: https://ross.abutalabs.com/products/electriceye
Language: Python
License: Apache-2.0
License Family: permissive
Topics: security-tools, security-audit, cloud-security, security-monitoring, aws-security, security-hub, cloud-compliance-reporting, cloud-auditing, security-engineering, devsecops, aws-audit, aws-compliance, compliance, attack-surface-management, aws, gcp-security, multicloud, saas-security, google-cloud-security, asset-management
Last push: 2026-02-09T03:04:44+00:00

## Health v2 (maintenance only)
Score: 62/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 66, release rhythm 35, longevity 100
- inputs: {"age_days": 2399, "days_push": 205, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1045, forks 138 (observed 2026-08-28T04:03:21.450180+00:00)

## What it is
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for asset management, security posture management, and attack surface monitoring. It evaluates hundreds of cloud and SaaS services and maps findings to over 20 industry, regulatory, and best-practice compliance frameworks.

## Use cases
- audit my AWS account for security misconfigurations
- continuously monitor security posture across multiple cloud providers
- discover and inventory cloud assets across AWS and GCP
- map cloud security findings to compliance frameworks like CIS or NIST
- monitor attack surface of SaaS applications
- export security findings to AWS Security Hub
- run cloud compliance audits from the CLI
- harden my CSP and SaaS environments with security controls

## When to choose
- you need multi-cloud (AWS, GCP) and SaaS security posture assessments from a single tool
- you want findings mapped to many compliance and regulatory frameworks
- you prefer a lightweight Python CLI or Docker-based scanner over a heavy commercial CSPM platform
- you want to centralize findings into AWS Security Hub or other outputs

## When to avoid
- you need a real-time runtime protection or workload (container/host) security agent
- you only use a single cloud with a native tool like AWS Security Hub or GCP Security Command Center already in place
- you require a GUI-driven enterprise CSPM with dashboards and workflows
- you need continuous vulnerability scanning of application code or containers rather than cloud configuration checks

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, monitoring, cli, developer-tools
- domain: security, cloud-computing, legal
- platform: cli, python, cloud
- tags: cloud-security-posture-management, attack-surface-management, asset-management, multi-cloud, saas-security, compliance-frameworks, aws-security-hub, devsecops, devops, docker

## Member repositories
- jonrau1/ElectricEye (main) score 62

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:21.450180+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:02:05.576383+00:00, confidence not recorded.
  - readme: https://github.com/jonrau1/ElectricEye (fetched 2026-08-28T04:03:21.450180+00:00, sha 4db2effdae53)
- Data as of 2026-08-30T08:39:29.467469+00:00.
