Comprehensive cloud security scanner for IAM and resource-based policies
Project description
Lock-And-Key
Lock & Key is a comprehensive cloud security scanner that analyzes IAM policies and resource-based policies across multiple cloud providers to identify security vulnerabilities, excessive permissions, and compliance issues.
Features
- Multi-Cloud Support: AWS (fully implemented), Azure (in progress), GCP (in progress)
- Comprehensive Policy Analysis: Scans IAM policies and resource-based policies across all supported services
- Security Vulnerability Detection: Identifies privilege escalation risks, wildcard permissions, and administrative access
- Interactive CLI: User-friendly command-line interface with rich formatting and progress indicators
- Detailed Reporting: Generates JSON reports with actionable findings and recommendations
- Least Privilege Analysis: Highlights violations of the principle of least privilege
Supported AWS Services
- IAM: Customer managed policies, roles, users
- S3: Bucket policies
- DynamoDB: Table resource policies
- Lambda: Function resource policies
- SNS: Topic policies
- SQS: Queue policies
- Glue: Data catalog and database policies
Installation
pip install lock-and-key
Usage
Interactive Mode
Run the interactive scanner to select providers and enter credentials:
lock-and-key interactive
Direct Scan Mode
Scan a specific provider with credentials:
# AWS with profile
lock-and-key scan --provider AWS --profile my-profile
# AWS with access keys
lock-and-key scan --provider AWS --access-key YOUR_KEY --secret-key YOUR_SECRET --region us-east-1
# Azure (in progress)
lock-and-key scan --provider Azure --client-id YOUR_ID --secret YOUR_SECRET --tenant-id YOUR_TENANT
# GCP (in progress)
lock-and-key scan --provider GCP --creds-path /path/to/service-account.json
Options
--output-dir: Specify output directory for reports (default:./reports)--provider: Choose cloud provider (AWS, Azure, GCP)- Various credential options for each provider
Security Checks
Lock & Key identifies the following security issues:
- Administrative Permissions: Policies with
*:*actions - Wildcard Resources: Policies allowing access to all resources (
*) - Privilege Escalation: IAM permissions that could lead to privilege escalation
- Overly Broad Access: Resource policies with excessive permissions
- Cross-Account Access: Policies allowing external account access
Report Format
Reports are generated in JSON format with the following structure:
{
"provider": "AWS",
"account_id": "123456789012",
"issues_found": 15,
"least_privilege_violations": 8,
"high_risk_permissions": 3,
"summary": "Scanned IAM and all resource policies. Found 15 security issues.",
"findings": [
{
"resource_name": "MyPolicy",
"resource_id": "arn:aws:iam::123456789012:policy/MyPolicy",
"issue_type": "Excessive Permissions",
"severity": "High",
"description": "Administrative permissions (*:*) detected",
"recommendation": "Replace wildcard permissions with specific actions"
}
]
}
Development
Requirements
- Python 3.8+
- boto3 (for AWS)
- click (CLI framework)
- rich (terminal formatting)
- pydantic (data validation)
Project Structure
lock_and_key/
├── cli.py # Command-line interface
├── core/
│ ├── scanner.py # Main scanner logic
│ └── ui.py # User interface utilities
├── providers/
│ ├── aws/ # AWS implementation
│ ├── azure.py # Azure (in progress)
│ └── gcp.py # GCP (in progress)
└── types/ # Data models and types
Cloud Provider Status
- ✅ AWS: Fully implemented with comprehensive policy analysis
- 🚧 Azure: In progress
- 🚧 GCP: In progress
License
lock-and-key is distributed under the terms of the MIT license.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file lock_and_key-1.0.tar.gz.
File metadata
- Download URL: lock_and_key-1.0.tar.gz
- Upload date:
- Size: 47.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.10.18
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cd87cc98b3bb967523f97147cab21e1c1c3110751a26f5f315c8095070a0bc65
|
|
| MD5 |
ae9f939423f1704667f08e05b4f0295f
|
|
| BLAKE2b-256 |
da49c3c9cab62d7f7a687acffb3c5a329072b8edbb7969556a9b993da1a802b0
|
File details
Details for the file lock_and_key-1.0-py3-none-any.whl.
File metadata
- Download URL: lock_and_key-1.0-py3-none-any.whl
- Upload date:
- Size: 21.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.10.18
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c02c8813e4b3a976eb1fb72885974ac8a0add01901802edfd586a37f27a47c6f
|
|
| MD5 |
d8822d717493697ae2913dfe4737a153
|
|
| BLAKE2b-256 |
c9ca415b91f854046d6c4d1db12f40efdbcab93969b73f2897df03a1cf525f04
|