# Scout Suite

Multi-Cloud Security Auditing Tool

Repository: https://github.com/nccgroup/ScoutSuite
Canonical: https://ross.abutalabs.com/products/scout-suite
Language: Python
License: GPL-2.0
License Family: copyleft
Topics: aws, azure, gcp, cloud, security, auditing
Last push: 2025-09-23T18:33:52+00:00
Link (homepage): http://nccgroup.github.io/Scout2/

## Health v2 (maintenance only)
Score: 42/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 43, release rhythm 8, longevity 100
- inputs: {"age_days": 2864, "days_push": 344, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 7801, forks 1228 (observed 2026-08-28T04:10:05.087724+00:00)

## What it is
Scout Suite is an open source multi-cloud security auditing tool that assesses the security posture of cloud environments. It gathers configuration data via cloud provider APIs and generates an offline HTML report highlighting risk areas and attack surface.

## Use cases
- audit my AWS account for security misconfigurations
- assess security posture of Azure and GCP environments
- find open security groups and exposed ports in my cloud account
- generate an HTML report of cloud configuration risks
- check IAM users for missing MFA and key rotation
- run a point-in-time security review of a Kubernetes cluster on a cloud provider

## When to choose
- you need a point-in-time, offline security assessment across AWS, Azure, or GCP
- you are a security consultant or auditor reviewing cloud account configuration
- you want an easy-to-read HTML report of cloud misconfigurations without touching web consoles

## When to avoid
- you need continuous, real-time cloud security monitoring rather than point-in-time audits
- you require automated remediation of findings rather than reporting
- you need runtime threat detection or intrusion detection

## Facets
- artifact type: cli-tool
- maturity: stable
- function: security, vulnerability-scanning, monitoring, cli
- domain: security, cloud-computing, penetration-testing
- platform: python, cli, cross-platform
- tags: cloud-security, security-audit, aws, azure, gcp, posture-assessment, html-report, multi-cloud, devops, docker

## Member repositories
- nccgroup/ScoutSuite (main) score 42
- nccgroup/Scout2 (mirror) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:05.087724+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:34:38.260906+00:00, confidence not recorded.
  - readme: https://github.com/nccgroup/ScoutSuite (fetched 2026-08-28T04:10:05.087724+00:00, sha f19aabeb09c3)
  - homepage: http://nccgroup.github.io/Scout2/ (fetched 2026-08-29T08:30:51.449073+00:00, sha 69a3750436c3)
  - registry_pypi: https://pypi.org/pypi/scoutsuite/json (fetched 2026-08-29T08:30:51.451701+00:00, sha 03822fab6e74)
- Data as of 2026-08-30T08:39:29.467469+00:00.
