Skip to content

Latest commit

 

History

386 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

aws-security-viz

Build Status Gem Version Gem Downloads Docker image OpenSSF Scorecard License

See which AWS security groups can reach which, and which are open to the internet. aws-security-viz reads the EC2 security group configuration from the AWS API, or from the JSON written by aws ec2 describe-security-groups, and draws it as a graph.

HTML viewer: the dev VPC and its groups, the public peers 0.0.0.0/0 and ::/0, and a thick red edge from 0.0.0.0/0 to the dev-bastion group
  1. Output formats: a self-contained HTML viewer (the default; offline, with collapsed VPCs, "can X reach Y" queries, several layouts and light and dark themes, see the viewer tour), JSON, Mermaid, DOT, and any image format Graphviz supports.
  2. One region, several regions, or all regions in a single graph.
  3. Risky public ingress (0.0.0.0/0 or ::/0 on a sensitive port) is drawn as a dashed crimson edge, and --fail-on-risk turns it into exit status 2 for CI.

Other formats such as DOT, PNG, SVG and Mermaid are covered in the documentation. Graphviz draws this one:

Security group graph

Documentation: https://anaynayak.github.io/aws-security-viz/

Install

Ruby 3.3 or newer. Graphviz is needed only for image formats such as png and svg.

gem install aws_security_viz

Or run the published image, which has Ruby and Graphviz built in:

docker pull ghcr.io/anaynayak/aws-security-viz:<version>

Example

aws ec2 describe-security-groups > security_groups.json
aws_security_viz -o security_groups.json -f viz.html

Open viz.html in a browser. To query AWS directly, use --profile <profile_name> --region us-west-1 in place of -o.

Learn more

  1. Quickstart
  2. Outputs and the HTML viewer
  3. Configuration, opts.yml and exit codes
  4. Credentials and IAM
  5. Filtering and risk checks, including CI
  6. Troubleshooting

Also: SECURITY.md, CHANGELOG.md, CONTRIBUTING.md and CODE_OF_CONDUCT.md.

LICENSE

MIT, see LICENSE.md. The HTML viewer inlines vendored copies of Cytoscape.js, cytoscape-fcose, cose-base, layout-base, dagre and cytoscape-dagre, which are also MIT licensed; their notices are under lib/aws_security_viz/vendor/ and ship inside the gem.

About

Visualize your aws security groups.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

723 stars

Watchers

29 watching

Forks

Releases

Packages

Used by

Contributors

Languages