
cfn-nag
#Network & Cloud#Cloud Security
A tool for pillaging Docker registries to extract image manifests and configurations.
The cfn-nag Tool for Scanning CloudFormation Templates
The cfn-nag tool scans CloudFormation templates to find insecure infrastructure patterns. These include overly permissive IAM rules, security group rules, absence of access logs, lack of encryption, and the use of password literals.
Installation Options and Integration
You can install it using either gem or brew, and it can also be integrated into CodePipeline for automated scanning.
