Monitors AWS, GCP, OpenStack, and GitHub for policy changes and insecure configurations, tracking asset changes over time.
Security Monkey is an open-source security monitoring tool that tracks assets and configuration changes across AWS, GCP, OpenStack, and GitHub. It helps organizations detect insecure configurations and policy violations by providing a historical record of changes and alerting on risks. The tool offers a unified interface to manage security posture across multiple cloud platforms and version control systems.
Cloud security engineers, DevOps teams, and platform engineers responsible for maintaining security and compliance across AWS, GCP, OpenStack, and GitHub environments.
Developers choose Security Monkey for its extensible architecture, multi-platform support, and detailed change tracking, which provide greater visibility and control than native cloud monitoring tools alone. Its ability to monitor GitHub alongside cloud environments makes it uniquely valuable for holistic security management.
Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Supports AWS, GCP, OpenStack, and GitHub in a single tool, providing centralized security monitoring across diverse environments as highlighted in the README.
Remembers historical asset states and clearly displays configuration changes over time, enabling precise audit trails for security incidents.
Allows custom account types, watchers, auditors, and alerters via documented plugins, facilitating tailored security policies.
Offers a single UI to browse and search across all monitored accounts and services, streamlining security investigations.
The project is in maintenance mode with end-of-life in 2020, meaning no new features and only minor bug fixes, making it obsolete for future-proof deployments.
Built on CPython 2.7, which is deprecated and unsupported, posing security risks and compatibility issues with modern systems.
Breaking changes in version 1.0 require reviewing Quickstart and Autostarting docs, indicating a non-trivial setup and maintenance burden.
Netflix's support is reduced to bug fixes only, relying on community contributions, which may slow issue resolution and updates.
security_monkey is an open-source alternative to the following products:
A Google Cloud service that provides inventory and metadata about cloud resources, enabling asset discovery, monitoring, and policy analysis.
AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources, helping with compliance auditing, security analysis, and change management.