AWS IAM security scanner with multi-framework compliance mapping (CIS, PCI-DSS, HIPAA, SOC 2, ISO)
360
A comprehensive AWS IAM security scanner with 44 security checks across 7 categories and compliance mapping for 10 frameworks (128 controls). It includes privilege-escalation and confused-deputy detection, multi-threaded scanning, credential-report analysis, and interactive HTML dashboards. The scanner is read-only and never modifies AWS resources.
~/.aws is readable (see Credentials).docker pull tarekcheikh/iam-security-scanner:latest
# Show help
docker run --rm tarekcheikh/iam-security-scanner --help
# Run a scan with mounted AWS credentials, writing reports to ./output
docker run --rm \
-v ~/.aws:/root/.aws:ro \
-v "$(pwd)/output:/app/output" \
tarekcheikh/iam-security-scanner security
The image ENTRYPOINT is iam-security-scanner, so arguments after the image
name are passed straight to the CLI (for example security, --help).
The container reads AWS credentials either from a mounted profile directory or
from environment variables. The image intentionally runs as root so that a host
~/.aws/credentials file (mode 0600, owned by your user) is readable inside the
container.
Mounted profile (supports --profile):
docker run --rm \
-v ~/.aws:/root/.aws:ro \
-v "$(pwd)/output:/app/output" \
tarekcheikh/iam-security-scanner security --profile production
Environment variables (including temporary/assumed-role credentials):
docker run --rm \
-e AWS_ACCESS_KEY_ID \
-e AWS_SECRET_ACCESS_KEY \
-e AWS_SESSION_TOKEN \
-e AWS_DEFAULT_REGION=us-east-1 \
-v "$(pwd)/output:/app/output" \
tarekcheikh/iam-security-scanner security
Note: IAM Identity Center (SSO) sessions do not resolve inside the container.
Export process credentials first (for example
aws configure export-credentials --format env) and pass them as environment
variables.
44 checks across 7 categories:
iam:PassRole on *, NotAction with Allow, unused policies.sts:AssumeRole *, confused-deputy and
cross-account trust (organization-aware).128 controls mapped across 10 frameworks:
Each scan produces a 0-100 security score and reports in the mounted output
directory (default /app/output in the container, mapped to ./output):
Select the format with -f json|csv|html|all (default all).
The scanner needs read-only access only. Attach a policy granting iam:Get*,
iam:List*, iam:GenerateCredentialReport, access-analyzer:List*,
access-analyzer:Get*, and sts:GetCallerIdentity. The full minimal policy is
in the repository README. The scanner performs no write or delete actions.
latest: most recent release1.0.0: pinned versionImages are published for linux/amd64 and linux/arm64.
Content type
Image
Digest
sha256:d2268dd03…
Size
67.2 MB
Last updated
3 months ago
docker pull tarekcheikh/iam-security-scanner