E-SCO
ScoutSuite
NCC Group's open-source multi-cloud security-auditing tool that assesses AWS, Azure, GCP, Alibaba, and Oracle Cloud configuration and reports findings in an HTML report.
OVERVIEW
Scout Suite (github.com/nccgroup/ScoutSuite) is NCC Group's open-source, Python-based multi-cloud security-auditing tool. Using the read-only APIs each provider exposes, it gathers configuration data across AWS, Azure, GCP, and — in earlier-maturity support — Alibaba Cloud, Oracle Cloud Infrastructure, Kubernetes, and DigitalOcean, then evaluates that configuration against a large built-in rule set covering IAM, network exposure, storage, logging, and encryption.
Rather than leaving an assessor to click through dozens of console pages per service, Scout Suite renders results as a single, offline-browsable HTML report: a dashboard of flagged rules grouped by severity and service, with drill-down into the exact resource and configuration value that triggered each finding. Because data collection and report rendering are separate steps, the raw JSON results can be re-rendered or diffed later without re-querying the account.
USE CASES
Practical use cases
- 01
Auditing a client's AWS, Azure, or GCP account configuration during a cloud security assessment.
- 02
Producing a navigable HTML deliverable that non-technical stakeholders can browse without cloud console access.
- 03
Diffing configuration snapshots over time by re-running against saved JSON results.
- 04
Scoping follow-on manual testing by triaging Scout Suite's flagged high-severity findings first.
QUICK START
For a point-in-time configuration audit of a client's cloud account once read-only assessment credentials are provisioned, producing a report reviewers can navigate without console access.
- Install with `pip install scoutsuite` (or clone the repo for the latest ruleset).
- Provision read-only, client-approved credentials for the target cloud account (an IAM role/policy, service principal, or service account).
- Run the provider-specific command — `scout aws`, `scout azure`, or `scout gcp` — authenticating with those credentials.
- Let data collection finish, then open the generated HTML report from the `scoutsuite-report/` output directory.
- Triage findings by severity, cross-reference against the engagement scope, and export or archive the JSON results for later diffing.
scout aws --profile client-readonly-assessmentBEFORE YOU RUN IT
What to check before running it
Scout Suite still makes a large number of read API calls across every enabled service — confirm with the client that this volume of `List`/`Describe`/`Get` calls is expected and won't trip billing or API-throttling alarms.
Use dedicated, time-boxed, read-only credentials scoped to the assessment; never run it with standing production credentials.
Findings reflect a point-in-time snapshot of configuration, not runtime behavior — pair it with log review or manual testing to confirm exploitability.