Automated Risk & Governance Unified Scanner
The all-seeing AWS cloud security audit framework β a hundred eyes on your infrastructure, never all asleep at once. ποΈ
|
Scan repositories for hardcoded credentials with over 50+ patterns including AWS keys, API tokens, and private keys. Includes Shannon entropy detection. |
Comprehensive checks for S3, EC2, IAM, RDS, Lambda, VPC, and CloudTrail to ensure your cloud infrastructure follows best practices. |
|
Analyze Terraform, CloudFormation, Serverless, and Kubernetes files for security flaws before deployment using the Checkov engine. |
Visualize and analyze IAM permissions to detect privilege escalation paths and overly permissive policies using graph-based mapping. |
Argus streamlines your security auditing workflow. Here is the process flow:
graph TD
A[Start Scan] --> B{Select Scan Type}
B -->|Secrets| C[Cloning Repository]
C --> D[Regex & Entropy Analysis]
D --> E[Git History Scan]
B -->|Cloud| F[AWS API Calls]
F --> G[Resource Enumeration]
G --> H[Security Rule Check]
B -->|IaC| I[Parse Infrastructure Code]
I --> J[Checkov Policy Scan]
B -->|IAM| K[Fetch IAM Policies]
K --> L[Neo4j Graph Building]
L --> M[Privilege Path Analysis]
E --> N[Generate Report]
H --> N
J --> N
M --> N
N --> O((End))
style A fill:#4F46E5,stroke:#333,stroke-width:2px,color:#fff
style N fill:#10B981,stroke:#333,stroke-width:2px,color:#fff
style O fill:#EF4444,stroke:#333,stroke-width:2px,color:#fff
- Python 3.9+
- Docker & Docker Compose (for persistent storage)
- AWS CLI configured (for cloud scanning)
# 1. Clone the repository
git clone https://github.com/Garyson26/Argus-Framework.git
cd Argus
# 2. Set up virtual environment
python -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\activate
# 3. Install dependencies
pip install -e ".[dev]"
# 4. Start database services
docker-compose up -d postgres redis neo4j
# 5. Initialize database
argus init-dbGet up and running in seconds!
# 1. Verify installation
argus --version
# 2. Run a secret scan on a local repo
argus secret scan ./your-project
# 3. Scan your default AWS profile
argus cloud scan
# 4. View help for more commands
argus --helpFind hidden secrets in your code, even deep in git history.
argus secret scan ./target-repo --historyOptions:
--history: Scan full git history--entropy 4.5: Set custom entropy threshold--json: Output results in JSON format
Audit your AWS environment for security gaps.
argus cloud scan --profile production --regions us-east-1,us-west-2Options:
--profile: Specify AWS CLI profile--services s3,ec2,iam: Contextual scanning--fix: Attempt auto-remediation (Use with caution!)
Shift left by scanning your infrastructure code.
argus iac scan ./terraform-filesVisualize permission paths and find dangerous roles.
argus iam analyze --graphNote: Requires Neo4j service to be running.
The Argus framework is built for modularity and scalability.
C4Context
title System Context Diagram for Argus
Person(user, "Security Auditor", "Uses Argus to audit cloud security.")
System(argus, "Argus Framework", "CLI tool for scanning secrets, cloud config, IaC, and IAM.")
System_Ext(aws, "AWS Cloud", "Target environment for auditing.")
System_Ext(neo4j, "Neo4j Database", "Stores IAM graph relationships.")
System_Ext(postgres, "PostgreSQL", "Stores finding results and reports.")
Rel(user, argus, "Runs CLI commands")
Rel(argus, aws, "Reads configuration via API")
Rel(argus, neo4j, "Queries/Updates Graph")
Rel(argus, postgres, "Persists Audit Data")
Argus is licensed under the Apache License, Version 2.0.
