CloudGuard AI is a read-only Python CLI that scans AWS for common public exposure risks and produces both terminal output and an HTML report.
It currently checks:
- EC2 security groups with internet access to SSH, RDP, MySQL, PostgreSQL, or Redis
- Publicly accessible RDS database instances
- S3 buckets missing one or more Block Public Access settings
- IAM users with AdministratorAccess
- IAM access keys older than 90 days
- Disabled CloudTrail logging
The scanner does not modify AWS resources. Remediation commands are printed as guidance only.
- Severity summary for
CRITICAL,HIGH,MEDIUM, andLOW - Security score that starts at 100 and subtracts by severity
- AWS account ID, scan timestamp, and total findings
- Finding-level risk explanation
- Finding-level business impact
- Recommended fix for each issue
- AWS CLI remediation command for manual follow-up
- Modern responsive HTML dashboard at
reports/cloudguard-report.html - Automation-friendly exit codes
python -m pip install boto3 rich jinja2
$env:PYTHONPATH="src"
python -m cloudguard_ai.cli scan --region us-east-1Use your default AWS credentials:
cloudguard-ai scanUse a specific AWS profile and region:
cloudguard-ai scan --profile my-profile --region us-east-1After each scan, open the generated report:
start reports\cloudguard-report.htmlScan Summary
AWS Account ID 123456789012
Scan Timestamp 2026-06-15 08:30:00 UTC
Total Findings 7
Security Score 20/100
Severity Summary
CRITICAL 2
HIGH 3
MEDIUM 2
LOW 0
CloudGuard AI Findings
Service Resource Severity Region Issue
EC2 web-sg (sg-12345678) CRITICAL us-east-1 SSH port 22 is open to the internet: 0.0.0.0/0
RDS prod-db HIGH us-east-1 DB instance is publicly accessible
IAM deploy-user CRITICAL global IAM user has AdministratorAccess permissions
HTML report written to reports\cloudguard-report.html
The full terminal table and HTML report also include risk explanation, business impact, recommended fix, and a manual AWS CLI remediation command for every finding.
0: Scan completed and no findings were detected1: Scan completed and one or more findings were detected2: AWS credentials, profile, region, or API errors prevented a reliable scan
CloudGuard AI only needs read permissions for the checks it runs:
ec2:DescribeSecurityGroupsrds:DescribeDBInstancess3:ListAllMyBucketss3:GetBucketPublicAccessBlockiam:ListUsersiam:ListAttachedUserPoliciesiam:ListUserPoliciesiam:GetUserPolicyiam:ListAccessKeyscloudtrail:DescribeTrailscloudtrail:GetTrailStatussts:GetCallerIdentity
- Unused IAM credential checks
- GuardDuty posture checks
- Security Hub ASFF export
- JSON and CSV report formats
- Multi-region scan mode
- CI/CD policy gate mode
- Optional allowlist for approved public resources
