EN
ENNA

CloudFox vs Steampipe

GitHub Stats

2.3k
Stars
7.7k
226
Forks
332
7
Issues
27
14d ago
Updated
4d ago
MIT
License
AGPL-3.0
Go
Language
Go

About CloudFox

CloudFox is a tool for identifying exploitable attack paths within cloud infrastructures. It enumerates IAM permissions, secrets, and network exposure to uncover potential vulnerabilities in AWS and Azure environments. Written in Go, CloudFox helps security professionals assess the security posture of cloud deployments by revealing misconfigurations and access control weaknesses. The tool is essential for cloud security audits and penetration testing.

About Steampipe

Steampipe is an open-source tool from Turbot that lets you query cloud infrastructure, SaaS services, and more using standard SQL. Rather than learning dozens of CLI tools and API formats, you write SQL queries against a unified schema powered by PostgreSQL. With over 140 plugins covering AWS, Azure, GCP, Kubernetes, GitHub, Slack, and many others, Steampipe provides a single pane of glass for infrastructure visibility. Its compliance frameworks (called Mods) include pre-built benchmarks for CIS, NIST, PCI DSS, and SOC 2, making it a powerful tool for both security auditing and operational troubleshooting. Steampipe also supports dashboards for visualization and can export results in JSON, CSV, or markdown.

Platform Support

🐧linux🍎macos🪟windows
🐧linux🍎macos🪟windows

Tags

CloudFox only

cloud-attack-pathsiam-enumerationawsazure

Steampipe only

sqlcloud-auditcompliancemulti-cloudzero-etlpostgres