Skip to main content

vamp-iac-audit

Python 3.9+ Platform License AGPL-3.0 VampSecure Labs

Overview

vamp-iac-audit is a static analysis security auditor for Infrastructure-as-Code files. It recursively scans directories for Terraform HCL, AWS CloudFormation, and Helm chart configurations, detecting misconfigurations and insecure defaults aligned with CIS benchmarks, MITRE ATT&CK TTPs, and cloud provider security best practices. Findings are rated CRITICAL to LOW and exported to Console (Rich), JSON, or HTML.

Features

  • Terraform module (IAC-TF-001 to IAC-TF-010): security groups open to 0.0.0.0/0 (CRITICAL), public S3 ACLs (HIGH), IAM wildcard actions/resources (HIGH), publicly accessible RDS instances (HIGH), unencrypted root block devices (MEDIUM), sensitive variable names without sensitive = true (MEDIUM), hardcoded secrets (sk_, ghp_, AKIA) (CRITICAL), SSH/RDP open to the world (CRITICAL), RDS without backup retention (MEDIUM), GCP firewall open to 0.0.0.0/0 (HIGH)
  • CloudFormation module (IAC-CF-001 to IAC-CF-008): security groups with protocol -1 open to 0.0.0.0/0 (CRITICAL), public S3 access control (HIGH), IAM wildcard policies (HIGH), publicly accessible RDS (HIGH), unprotected password parameters missing NoEcho (MEDIUM), SSH/RDP open security groups (CRITICAL), KMS without key rotation (LOW), S3 without bucket encryption (MEDIUM)
  • Helm module (IAC-HLM-001 to IAC-HLM-008): privileged containers (CRITICAL), hostNetwork usage (HIGH), hostPID/hostIPC (HIGH), missing runAsNonRoot (MEDIUM), missing resource limits (MEDIUM), hardcoded secrets in env values (CRITICAL), auto-mounted service account tokens (LOW), dangerous Linux capabilities SYS_ADMIN/NET_ADMIN/SYS_PTRACE (HIGH)
  • Auto-detection of IaC type when no explicit flag is provided
  • Recursive directory scanning
  • Per-file findings with line numbers and resource names
  • MITRE ATT&CK and CIS Benchmark references per finding
  • Rich console output: findings table per file + summary by severity, IaC type and module
  • Export to JSON (machine-readable) and HTML (standalone dark-theme)
  • Exit code 1 on CRITICAL/HIGH findings for CI/CD pipeline integration

Requirements

  • Python 3.9 or later
  • rich >= 13.7.0
  • pyyaml >= 6.0

Installation

pip install vamp-iac-audit
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-iac-audit
git clone https://github.com/Vampsecure-Labs/vamp-iac-audit.git
cd vamp-iac-audit
python3 -m venv .venv
source .venv/bin/activate   # Windows: .venv\Scripts\activate
pip install -r requirements.txt

Usage

vamp-iac-audit scan --help
usage: vamp-iac-audit scan [-h] --path DIR
                            [--terraform] [--cloudformation] [--helm]
                            [--json FILE] [--html FILE]

Examples

# Scan all IaC types in current directory (auto-detect)
vamp-iac-audit scan --path .

# Scan only Terraform files
vamp-iac-audit scan --path ./infra --terraform

# Scan only CloudFormation templates
vamp-iac-audit scan --path ./cfn --cloudformation

# Scan only Helm charts
vamp-iac-audit scan --path ./charts --helm

# Export findings to JSON and HTML
vamp-iac-audit scan --path ./infra --json results.json --html report.html

# Scan multiple types explicitly
vamp-iac-audit scan --path ./infra --terraform --cloudformation

CLI Reference

Flag Default Description
--path DIR required Directory to scan recursively
--terraform auto Scan Terraform .tf and .tfvars files
--cloudformation auto Scan CloudFormation YAML/JSON templates
--helm auto Scan Helm chart templates/*.yaml files
--json FILE — Export results to JSON
--html FILE — Export dark-theme standalone HTML report

Output Formats

Format Flag Description
Console (default) Rich tables per file with color-coded findings by severity
JSON --json FILE Machine-readable full result set
HTML --html FILE Dark-theme standalone report

Checks Reference

Terraform (IAC-TF-*)

ID Check Severity MITRE
IAC-TF-001 aws_security_group with cidr_blocks = ["0.0.0.0/0"] on ingress CRITICAL T1190
IAC-TF-002 aws_s3_bucket with acl = "public-read" or "public-read-write" HIGH T1530
IAC-TF-003 aws_iam_policy with Action = "*" or Resource = "*" HIGH T1098
IAC-TF-004 aws_db_instance with publicly_accessible = true HIGH T1190
IAC-TF-005 aws_instance/aws_launch_template without encrypted on root block device MEDIUM T1486
IAC-TF-006 Variable with sensitive = false and name containing password/secret/key/token MEDIUM T1552
IAC-TF-007 Hardcoded secret value pattern (sk_, ghp_, AKIA) CRITICAL T1552
IAC-TF-008 aws_security_group with port 22 or 3389 open to 0.0.0.0/0 CRITICAL T1021
IAC-TF-009 aws_rds_cluster without backup_retention_period or set to 0 MEDIUM T1485
IAC-TF-010 google_compute_firewall with source_ranges = ["0.0.0.0/0"] HIGH T1190

CloudFormation (IAC-CF-*)

ID Check Severity
IAC-CF-001 SecurityGroup with IpProtocol: "-1" and CidrIp: "0.0.0.0/0" CRITICAL
IAC-CF-002 S3 with AccessControl: PublicRead or PublicReadWrite HIGH
IAC-CF-003 IAM Policy with Action: "*" or Resource: "*" HIGH
IAC-CF-004 RDS with PubliclyAccessible: true HIGH
IAC-CF-005 String parameter without NoEcho: true and name containing password/secret/key MEDIUM
IAC-CF-006 SecurityGroup with port 22/3389 open to 0.0.0.0/0 CRITICAL
IAC-CF-007 KMS without EnableKeyRotation: true LOW
IAC-CF-008 S3 without BucketEncryption configured MEDIUM

Helm (IAC-HLM-*)

ID Check Severity
IAC-HLM-001 securityContext.privileged: true CRITICAL
IAC-HLM-002 hostNetwork: true HIGH
IAC-HLM-003 hostPID: true or hostIPC: true HIGH
IAC-HLM-004 Missing securityContext.runAsNonRoot: true MEDIUM
IAC-HLM-005 Missing resources.limits in containers MEDIUM
IAC-HLM-006 Env value with hardcoded secret pattern (sk_, ghp_, AKIA, ey...) CRITICAL
IAC-HLM-007 serviceAccount.automountServiceAccountToken: true (default) LOW
IAC-HLM-008 capabilities.add with SYS_ADMIN, NET_ADMIN, or SYS_PTRACE HIGH

Exit Codes

Code Meaning CI/CD Behavior
0 No critical or high findings Pipeline passes
1 Critical or high findings detected Pipeline fails — review required
2 Execution error Pipeline fails — check configuration

Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.

Part of VampSecure Labs Toolkit

vamp-iac-audit is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:


© VampSecure Studios — VampSecure Labs Security Research Division

Versión

v1.0 — VampSecure Labs Security Research Division

Metadata

Release files for vamp-iac-audit 1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-iac-audit 1.0
File Size Uploaded
vamp_iac_audit-1.0.tar.gz 28.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-iac-audit 1.0
File Interpreter ABI Platform
vamp_iac_audit-1.0-py3-none-any.whl Python 3 none any Details

Total release size: 57.9 kB

Release files / vamp_iac_audit-1.0.tar.gz

Download URL vamp_iac_audit-1.0.tar.gz
Size 28.3 kB
Tags Source
SHA-256 checksum
How to use checksums
c768fdb2d94e5d253a0ae53bc3ddea6179fbf563c72f6659e25c556040879c51
BLAKE2b-256 checksum
How to use checksums
08d24529f741137714931c91ad216930a66041edb456f75093443fd9b57ed374
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / vamp_iac_audit-1.0-py3-none-any.whl

Download URL vamp_iac_audit-1.0-py3-none-any.whl
Size 29.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
308fd2f9e89d07e7694fb41af6c7b5f854a382dee8ab33ee07f0b3864c7bdff2
BLAKE2b-256 checksum
How to use checksums
8598a086a8f6ae67647b8fd44519c3506eda3a575851d5bdb874d23895800bde
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

This release

1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page