vamp-iac-audit
Overview
vamp-iac-audit is a static analysis security auditor for Infrastructure-as-Code files. It recursively scans directories for Terraform HCL, AWS CloudFormation, and Helm chart configurations, detecting misconfigurations and insecure defaults aligned with CIS benchmarks, MITRE ATT&CK TTPs, and cloud provider security best practices. Findings are rated CRITICAL to LOW and exported to Console (Rich), JSON, or HTML.
Features
- Terraform module (IAC-TF-001 to IAC-TF-010): security groups open to
0.0.0.0/0(CRITICAL), public S3 ACLs (HIGH), IAM wildcard actions/resources (HIGH), publicly accessible RDS instances (HIGH), unencrypted root block devices (MEDIUM), sensitive variable names withoutsensitive = true(MEDIUM), hardcoded secrets (sk_,ghp_,AKIA) (CRITICAL), SSH/RDP open to the world (CRITICAL), RDS without backup retention (MEDIUM), GCP firewall open to0.0.0.0/0(HIGH) - CloudFormation module (IAC-CF-001 to IAC-CF-008): security groups with protocol
-1open to0.0.0.0/0(CRITICAL), public S3 access control (HIGH), IAM wildcard policies (HIGH), publicly accessible RDS (HIGH), unprotected password parameters missingNoEcho(MEDIUM), SSH/RDP open security groups (CRITICAL), KMS without key rotation (LOW), S3 without bucket encryption (MEDIUM) - Helm module (IAC-HLM-001 to IAC-HLM-008): privileged containers (CRITICAL), hostNetwork usage (HIGH), hostPID/hostIPC (HIGH), missing
runAsNonRoot(MEDIUM), missing resource limits (MEDIUM), hardcoded secrets in env values (CRITICAL), auto-mounted service account tokens (LOW), dangerous Linux capabilitiesSYS_ADMIN/NET_ADMIN/SYS_PTRACE(HIGH) - Auto-detection of IaC type when no explicit flag is provided
- Recursive directory scanning
- Per-file findings with line numbers and resource names
- MITRE ATT&CK and CIS Benchmark references per finding
- Rich console output: findings table per file + summary by severity, IaC type and module
- Export to JSON (machine-readable) and HTML (standalone dark-theme)
- Exit code 1 on CRITICAL/HIGH findings for CI/CD pipeline integration
Requirements
- Python 3.9 or later
rich >= 13.7.0pyyaml >= 6.0
Installation
pip install vamp-iac-audit
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-iac-audit
git clone https://github.com/Vampsecure-Labs/vamp-iac-audit.git
cd vamp-iac-audit
python3 -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -r requirements.txt
Usage
vamp-iac-audit scan --help
usage: vamp-iac-audit scan [-h] --path DIR
[--terraform] [--cloudformation] [--helm]
[--json FILE] [--html FILE]
Examples
# Scan all IaC types in current directory (auto-detect)
vamp-iac-audit scan --path .
# Scan only Terraform files
vamp-iac-audit scan --path ./infra --terraform
# Scan only CloudFormation templates
vamp-iac-audit scan --path ./cfn --cloudformation
# Scan only Helm charts
vamp-iac-audit scan --path ./charts --helm
# Export findings to JSON and HTML
vamp-iac-audit scan --path ./infra --json results.json --html report.html
# Scan multiple types explicitly
vamp-iac-audit scan --path ./infra --terraform --cloudformation
CLI Reference
| Flag | Default | Description |
|---|---|---|
--path DIR |
required | Directory to scan recursively |
--terraform |
auto | Scan Terraform .tf and .tfvars files |
--cloudformation |
auto | Scan CloudFormation YAML/JSON templates |
--helm |
auto | Scan Helm chart templates/*.yaml files |
--json FILE |
— | Export results to JSON |
--html FILE |
— | Export dark-theme standalone HTML report |
Output Formats
| Format | Flag | Description |
|---|---|---|
| Console | (default) | Rich tables per file with color-coded findings by severity |
| JSON | --json FILE |
Machine-readable full result set |
| HTML | --html FILE |
Dark-theme standalone report |
Checks Reference
Terraform (IAC-TF-*)
| ID | Check | Severity | MITRE |
|---|---|---|---|
| IAC-TF-001 | aws_security_group with cidr_blocks = ["0.0.0.0/0"] on ingress |
CRITICAL | T1190 |
| IAC-TF-002 | aws_s3_bucket with acl = "public-read" or "public-read-write" |
HIGH | T1530 |
| IAC-TF-003 | aws_iam_policy with Action = "*" or Resource = "*" |
HIGH | T1098 |
| IAC-TF-004 | aws_db_instance with publicly_accessible = true |
HIGH | T1190 |
| IAC-TF-005 | aws_instance/aws_launch_template without encrypted on root block device |
MEDIUM | T1486 |
| IAC-TF-006 | Variable with sensitive = false and name containing password/secret/key/token |
MEDIUM | T1552 |
| IAC-TF-007 | Hardcoded secret value pattern (sk_, ghp_, AKIA) |
CRITICAL | T1552 |
| IAC-TF-008 | aws_security_group with port 22 or 3389 open to 0.0.0.0/0 |
CRITICAL | T1021 |
| IAC-TF-009 | aws_rds_cluster without backup_retention_period or set to 0 |
MEDIUM | T1485 |
| IAC-TF-010 | google_compute_firewall with source_ranges = ["0.0.0.0/0"] |
HIGH | T1190 |
CloudFormation (IAC-CF-*)
| ID | Check | Severity |
|---|---|---|
| IAC-CF-001 | SecurityGroup with IpProtocol: "-1" and CidrIp: "0.0.0.0/0" |
CRITICAL |
| IAC-CF-002 | S3 with AccessControl: PublicRead or PublicReadWrite |
HIGH |
| IAC-CF-003 | IAM Policy with Action: "*" or Resource: "*" |
HIGH |
| IAC-CF-004 | RDS with PubliclyAccessible: true |
HIGH |
| IAC-CF-005 | String parameter without NoEcho: true and name containing password/secret/key |
MEDIUM |
| IAC-CF-006 | SecurityGroup with port 22/3389 open to 0.0.0.0/0 |
CRITICAL |
| IAC-CF-007 | KMS without EnableKeyRotation: true |
LOW |
| IAC-CF-008 | S3 without BucketEncryption configured |
MEDIUM |
Helm (IAC-HLM-*)
| ID | Check | Severity |
|---|---|---|
| IAC-HLM-001 | securityContext.privileged: true |
CRITICAL |
| IAC-HLM-002 | hostNetwork: true |
HIGH |
| IAC-HLM-003 | hostPID: true or hostIPC: true |
HIGH |
| IAC-HLM-004 | Missing securityContext.runAsNonRoot: true |
MEDIUM |
| IAC-HLM-005 | Missing resources.limits in containers |
MEDIUM |
| IAC-HLM-006 | Env value with hardcoded secret pattern (sk_, ghp_, AKIA, ey...) |
CRITICAL |
| IAC-HLM-007 | serviceAccount.automountServiceAccountToken: true (default) |
LOW |
| IAC-HLM-008 | capabilities.add with SYS_ADMIN, NET_ADMIN, or SYS_PTRACE |
HIGH |
Exit Codes
| Code | Meaning | CI/CD Behavior |
|---|---|---|
0 |
No critical or high findings | Pipeline passes |
1 |
Critical or high findings detected | Pipeline fails — review required |
2 |
Execution error | Pipeline fails — check configuration |
Legal Notice
Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.
Part of VampSecure Labs Toolkit
vamp-iac-audit is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:
- Portfolio: github.com/Vampsecure-Labs
- Orchestrator: github.com/Vampsecure-Labs/vamp-orchestrator
© VampSecure Studios — VampSecure Labs Security Research Division
Versión
v1.0 — VampSecure Labs Security Research Division
Metadata
Release files for vamp-iac-audit 1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_iac_audit-1.0.tar.gz | 28.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_iac_audit-1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 57.9 kB
Release files / vamp_iac_audit-1.0.tar.gz
| Download URL | vamp_iac_audit-1.0.tar.gz |
|---|---|
| Size | 28.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c768fdb2d94e5d253a0ae53bc3ddea6179fbf563c72f6659e25c556040879c51
|
|
BLAKE2b-256 checksum How to use checksums |
08d24529f741137714931c91ad216930a66041edb456f75093443fd9b57ed374
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / vamp_iac_audit-1.0-py3-none-any.whl
| Download URL | vamp_iac_audit-1.0-py3-none-any.whl |
|---|---|
| Size | 29.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
308fd2f9e89d07e7694fb41af6c7b5f854a382dee8ab33ee07f0b3864c7bdff2
|
|
BLAKE2b-256 checksum How to use checksums |
8598a086a8f6ae67647b8fd44519c3506eda3a575851d5bdb874d23895800bde
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|