Skip to main content

AWS Sentinel

PyPI version GitHub stars Downloads License: MIT

AWS Sentinel is a powerful command-line security scanner for AWS resources. It helps identify common security issues and misconfigurations in your AWS environment. Now featuring natural language queries powered by Amazon Bedrock!

 █████╗ ██╗    ██╗███████╗    ███████╗███████╗███╗   ██╗████████╗██╗███╗   ██╗███████╗██╗     
██╔══██╗██║    ██║██╔════╝    ██╔════╝██╔════╝████╗  ██║╚══██╔══╝██║████╗  ██║██╔════╝██║     
███████║██║ █╗ ██║███████╗    ███████╗█████╗  ██╔██╗ ██║   ██║   ██║██╔██╗ ██║█████╗  ██║     
██╔══██║██║███╗██║╚════██║    ╚════██║██╔══╝  ██║╚██╗██║   ██║   ██║██║╚██╗██║██╔══╝  ██║     
██║  ██║╚███╔███╔╝███████║    ███████║███████╗██║ ╚████║   ██║   ██║██║ ╚████║███████╗███████╗
╚═╝  ╚═╝ ╚══╝╚══╝ ╚══════╝    ╚══════╝╚══════╝╚═╝  ╚═══╝   ╚═╝   ╚═╝╚═╝  ╚═══╝╚══════╝╚══════╝
                                                                        
                      AWS Security Sentinel

Scanning AWS account using profile: default in region: us-east-1
Initializing security checks...
+-------------------------+
| AWS Security Issues Detected |
+--------+---------------+------------------------------------------+
| Service| Resource      | Issue                                    |
+--------+---------------+------------------------------------------+
| S3     | mybucket      | Public bucket                            |
| EC2    | sg-12345abcde | Security group with port 22 open to public |
| EBS    | vol-67890fghij| Unencrypted volume                       |
| IAM    | alice         | User without MFA                         |
+--------+---------------+------------------------------------------+

Features

AWS Sentinel currently checks for the following security issues:

  • S3 Buckets: Identifies publicly accessible buckets
  • EC2 Security Groups: Finds security groups with port 22 (SSH) open to the public
  • EBS Volumes: Detects unencrypted volumes
  • IAM Users: Identifies users without Multi-Factor Authentication (MFA)

🆕 Natural Language Queries (Powered by Amazon Bedrock)

Ask security questions in plain English! AWS Sentinel now supports natural language queries using Amazon Bedrock's Nova Lite model.

Examples:

  • "Are there any public S3 buckets?"
  • "Check for high priority security issues"
  • "Find IAM users without MFA"
  • "Show me unencrypted storage volumes"

Installation

You can install AWS Sentinel using pip:

pip install aws-sentinel

Or using uv

uv pip install aws-sentinel

Usage

Natural Language Queries 🆕

Ask security questions in plain English using Amazon Bedrock:

aws-sentinel ask "Are there any public S3 buckets?"
aws-sentinel ask "Check for high priority security issues"
aws-sentinel ask "Find IAM users without MFA"

Natural Language Options:

Usage: aws-sentinel ask [OPTIONS] QUERY

Options:
  --profile TEXT               AWS profile to use for authentication
  --region TEXT                AWS region to scan for security issues
  --bedrock-region TEXT        AWS region for Amazon Bedrock service
  --output [table|json|csv]    Output format for scan results
  -v, --verbose                Enable verbose output
  -h, --help                   Show this message and exit.

Traditional Scanning

Run a full security scan using your default AWS profile:

aws-sentinel scan

If you don't specify a profile or region, it will use the default profile and us-east-1 region.

Command Options

Usage: aws-sentinel scan [OPTIONS]

Options:
  --profile TEXT               AWS profile to use for authentication (from
                               ~/.aws/credentials)
  --region TEXT                AWS region to scan for security issues
  --checks TEXT                Comma-separated list of checks to run
                               (s3,ec2,ebs,iam) or "all"
  --output [table|json|csv]    Output format for scan results
  --severity [low|medium|high|all]
                               Filter results by minimum severity level
  -v, --verbose                Enable verbose output
  -h, --help                   Show this message and exit.

Examples

Natural Language Queries:

# Ask about specific services
aws-sentinel ask "Are there any public S3 buckets in my account?"

# Check for critical issues
aws-sentinel ask "What are the most critical security problems?"

# Filter by service type
aws-sentinel ask "Check IAM users for security issues"

# Export natural language results
aws-sentinel ask "Find all security issues" --output json > nl_security_report.json

Traditional Scanning:

Run a scan with a specific AWS profile and region:

aws-sentinel scan --profile production --region us-west-2

Run only specific security checks:

aws-sentinel scan --checks s3,iam

Export results in JSON format:

aws-sentinel scan --output json > security_report.json

Export results in CSV format:

aws-sentinel scan --output csv > security_report.csv

Show only high severity issues:

aws-sentinel scan --severity high

Get detailed documentation:

aws-sentinel docs

Example Output

Table Format (Default)

 █████╗ ██╗    ██╗███████╗    ███████╗███████╗███╗   ██╗████████╗██╗███╗   ██╗███████╗██╗     
██╔══██╗██║    ██║██╔════╝    ██╔════╝██╔════╝████╗  ██║╚══██╔══╝██║████╗  ██║██╔════╝██║     
███████║██║ █╗ ██║███████╗    ███████╗█████╗  ██╔██╗ ██║   ██║   ██║██╔██╗ ██║█████╗  ██║     
██╔══██║██║███╗██║╚════██║    ╚════██║██╔══╝  ██║╚██╗██║   ██║   ██║██║╚██╗██║██╔══╝  ██║     
██║  ██║╚███╔███╔╝███████║    ███████║███████╗██║ ╚████║   ██║   ██║██║ ╚████║███████╗███████╗
╚═╝  ╚═╝ ╚══╝╚══╝ ╚══════╝    ╚══════╝╚══════╝╚═╝  ╚═══╝   ╚═╝   ╚═╝╚═╝  ╚═══╝╚══════╝╚══════╝
                                                                        
                      AWS Security Sentinel

Scanning AWS account using profile: default in region: us-east-1
Initializing security checks...
+-------------------------+
| AWS Security Issues Detected |
+--------+---------------+------------------------------------------+
| Service| Resource      | Issue                                    |
+--------+---------------+------------------------------------------+
| S3     | mybucket      | Public bucket                            |
| EC2    | sg-12345abcde | Security group with port 22 open to public |
| EBS    | vol-67890fghij| Unencrypted volume                       |
| IAM    | alice         | User without MFA                         |
+--------+---------------+------------------------------------------+

JSON Format

{
  "scan_results": {
    "profile": "default",
    "region": "us-east-1",
    "scan_time": "2025-04-15T14:32:17.654321",
    "issues_count": 3,
    "issues": [
      {
        "service": "S3",
        "resource": "public-bucket",
        "issue": "Public bucket",
        "severity": "HIGH"
      },
      {
        "service": "EC2",
        "resource": "sg-12345abcde",
        "issue": "Security group with port 22 open to public",
        "severity": "HIGH"
      },
      {
        "service": "IAM",
        "resource": "admin-user",
        "issue": "User without MFA",
        "severity": "HIGH"
      }
    ]
  }
}

Requirements

  • Python 3.9+
  • AWS credentials configured (via AWS CLI or environment variables)
  • Required permissions to access AWS resources
  • For natural language queries: Access to Amazon Bedrock with Nova Lite model

Amazon Bedrock Setup

To use natural language queries, ensure you have:

  1. Access to Amazon Bedrock in your AWS account
  2. Model access to amazon.nova-lite-v1:0
  3. Appropriate IAM permissions for Bedrock:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "bedrock:InvokeModel"
          ],
          "Resource": "arn:aws:bedrock:*::foundation-model/amazon.nova-lite-v1:0"
        }
      ]
    }
    

Note: If Bedrock is unavailable, the tool automatically falls back to keyword-based parsing.

Development

To set up the project for development:

  1. Clone the repository:

    git clone https://github.com/rishabkumar7/aws-sentinel.git
    cd aws-sentinel
    
  2. Create a virtual environment:

    python -m venv venv
    source venv/bin/activate  # On Windows: venv\Scripts\activate    
    
  3. Install development dependencies:

    pip install -e '.[dev]'
    
  4. Run the tests:

    python -m unittest discover tests
    

License

MIT License

Contributing

Contributions are welcome! Please feel free to submit an Issue and a Pull Request.

Metadata

Release files for aws-sentinel 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aws-sentinel 0.1.2
File Size Uploaded
aws_sentinel-0.1.2.tar.gz 16.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aws-sentinel 0.1.2
File Interpreter ABI Platform
aws_sentinel-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 32.7 kB

Release files / aws_sentinel-0.1.2.tar.gz

Download URL aws_sentinel-0.1.2.tar.gz
Size 16.0 kB
Tags Source
SHA-256 checksum
How to use checksums
173bf89353688b8928d216d85cc05952fc5e287b45d43d8a6b3efb76bd1211f8
BLAKE2b-256 checksum
How to use checksums
495d0af4d12a76ffff6ac7a290deffd163185bf07349fc139f87307729d62b2c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.4

Release files / aws_sentinel-0.1.2-py3-none-any.whl

Download URL aws_sentinel-0.1.2-py3-none-any.whl
Size 16.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
85093750ae45f96b9f5b816f26c428cb6f762ede6deb2f3370da0930631f1b14
BLAKE2b-256 checksum
How to use checksums
6e35e5bc9648cc7275021bef2ff0852a02a03f3527ce5fcefb58170951463a7c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.4

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page