ScoutSuite
scout aws
Audits AWS (and other clouds) security with ScoutSuite, generating the HTML report of the account's posture.
Run it when you need a cloud security audit with a visual report: ScoutSuite assesses the account (AWS, Azure, GCP) — services, IAM policies, buckets, security groups — and generates a navigable HTML report with findings by service and severity. It's the reference multi-cloud auditing tool (the successor to Scout2): the account's posture in a report that can be shared and reviewed without extra tools. For hardening and periodic reviews, ScoutSuite is the visual alternative to Prowler: findings by service (S3, IAM, EC2) are reviewed and remediated.
Don't use it for intrusion detection: ScoutSuite audits configuration, not behavior. The ScoutSuite project is in reduced maintenance (development slowed compared to Prowler): for current AWS auditing, Prowler is the reference and ScoutSuite is the historical complement. And watch out for permissions: the audit needs a broad read policy — grant least privilege and scope it down (--services). The full report for a large account takes time, and findings require triage by severity. For continuous posture, Security Hub / Defender / SCC are the managed layer; ScoutSuite is for point-in-time audits.