EN
ENNA

CloudSploit vs Steampipe

GitHub Stats

3.7k
Stars
7.7k
739
Forks
332
207
Issues
27
1mo ago
Updated
4d ago
GPL-3.0
License
AGPL-3.0
JavaScript
Language
Go

About CloudSploit

CloudSploit is an open-source security configuration scanner for cloud environments, including AWS, Azure, GCP, and Oracle Cloud. It detects misconfigurations and security risks by analyzing cloud service settings against best practices. Written in JavaScript, CloudSploit is used by security teams to identify vulnerabilities in cloud infrastructure and ensure compliance with security standards. Its comprehensive coverage makes it a critical tool for cloud security monitoring.

About Steampipe

Steampipe is an open-source tool from Turbot that lets you query cloud infrastructure, SaaS services, and more using standard SQL. Rather than learning dozens of CLI tools and API formats, you write SQL queries against a unified schema powered by PostgreSQL. With over 140 plugins covering AWS, Azure, GCP, Kubernetes, GitHub, Slack, and many others, Steampipe provides a single pane of glass for infrastructure visibility. Its compliance frameworks (called Mods) include pre-built benchmarks for CIS, NIST, PCI DSS, and SOC 2, making it a powerful tool for both security auditing and operational troubleshooting. Steampipe also supports dashboards for visualization and can export results in JSON, CSV, or markdown.

Platform Support

🐧linux🍎macos🪟windows
🐧linux🍎macos🪟windows

Tags

CloudSploit only

cloud-securitymisconfigurationawsazure

Steampipe only

sqlcloud-auditcompliancemulti-cloudzero-etlpostgres