cfn-nag

cfn-nag

#Network & Cloud#Cloud Security

A tool for pillaging Docker registries to extract image manifests and configurations.

Visit Website

The cfn-nag Tool for Scanning CloudFormation Templates

The cfn-nag tool scans CloudFormation templates to find insecure infrastructure patterns. These include overly permissive IAM rules, security group rules, absence of access logs, lack of encryption, and the use of password literals.

Installation Options and Integration

You can install it using either gem or brew, and it can also be integrated into CodePipeline for automated scanning.