Metadata-Version: 2.4
Name: vamp-iac-audit
Version: 1.0
Summary: Infrastructure-as-Code security auditor: Terraform, CloudFormation and Helm static analysis
Author-email: VampSecure Studios <contact@vampsecurestudios.com>
License: AGPL-3.0-only
Project-URL: Homepage, https://github.com/Vampsecure-Labs/vamp-iac-audit
Project-URL: Repository, https://github.com/Vampsecure-Labs/vamp-iac-audit
Keywords: security,pentest,terraform,cloudformation,helm,iac,devsecops,vampsecure,cloud
Classifier: Development Status :: 5 - Production/Stable
Classifier: Environment :: Console
Classifier: Intended Audience :: Information Technology
Classifier: License :: OSI Approved :: GNU Affero General Public License v3 or later (AGPLv3+)
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Topic :: Security
Requires-Python: >=3.9
Description-Content-Type: text/markdown
Requires-Dist: rich>=13.7.0
Requires-Dist: pyyaml>=6.0

<!-- © VampSecure Studios — VampSecure Labs Security Research Division -->
<h1 align="center">vamp-iac-audit</h1>

<p align="center">
  <img src="https://img.shields.io/badge/python-3.9%2B-blue?logo=python&logoColor=white" alt="Python 3.9+"/>
  <img src="https://img.shields.io/badge/platform-linux%20%7C%20macOS%20%7C%20windows-lightgrey" alt="Platform"/>
  <img src="https://img.shields.io/badge/license-AGPL--3.0-green" alt="License AGPL-3.0"/>
  <img src="https://img.shields.io/badge/VampSecure-Labs-magenta" alt="VampSecure Labs"/>
</p>

## Overview

`vamp-iac-audit` is a static analysis security auditor for Infrastructure-as-Code files. It recursively scans directories for Terraform HCL, AWS CloudFormation, and Helm chart configurations, detecting misconfigurations and insecure defaults aligned with CIS benchmarks, MITRE ATT&CK TTPs, and cloud provider security best practices. Findings are rated CRITICAL to LOW and exported to Console (Rich), JSON, or HTML.

## Features

- **Terraform module** (IAC-TF-001 to IAC-TF-010): security groups open to `0.0.0.0/0` (CRITICAL), public S3 ACLs (HIGH), IAM wildcard actions/resources (HIGH), publicly accessible RDS instances (HIGH), unencrypted root block devices (MEDIUM), sensitive variable names without `sensitive = true` (MEDIUM), hardcoded secrets (`sk_`, `ghp_`, `AKIA`) (CRITICAL), SSH/RDP open to the world (CRITICAL), RDS without backup retention (MEDIUM), GCP firewall open to `0.0.0.0/0` (HIGH)
- **CloudFormation module** (IAC-CF-001 to IAC-CF-008): security groups with protocol `-1` open to `0.0.0.0/0` (CRITICAL), public S3 access control (HIGH), IAM wildcard policies (HIGH), publicly accessible RDS (HIGH), unprotected password parameters missing `NoEcho` (MEDIUM), SSH/RDP open security groups (CRITICAL), KMS without key rotation (LOW), S3 without bucket encryption (MEDIUM)
- **Helm module** (IAC-HLM-001 to IAC-HLM-008): privileged containers (CRITICAL), hostNetwork usage (HIGH), hostPID/hostIPC (HIGH), missing `runAsNonRoot` (MEDIUM), missing resource limits (MEDIUM), hardcoded secrets in env values (CRITICAL), auto-mounted service account tokens (LOW), dangerous Linux capabilities `SYS_ADMIN`/`NET_ADMIN`/`SYS_PTRACE` (HIGH)
- Auto-detection of IaC type when no explicit flag is provided
- Recursive directory scanning
- Per-file findings with line numbers and resource names
- MITRE ATT&CK and CIS Benchmark references per finding
- Rich console output: findings table per file + summary by severity, IaC type and module
- Export to JSON (machine-readable) and HTML (standalone dark-theme)
- Exit code 1 on CRITICAL/HIGH findings for CI/CD pipeline integration

## Requirements

- Python 3.9 or later
- `rich >= 13.7.0`
- `pyyaml >= 6.0`

## Installation

```bash
pip install vamp-iac-audit
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-iac-audit
```

```bash
git clone https://github.com/Vampsecure-Labs/vamp-iac-audit.git
cd vamp-iac-audit
python3 -m venv .venv
source .venv/bin/activate   # Windows: .venv\Scripts\activate
pip install -r requirements.txt
```

## Usage

```
vamp-iac-audit scan --help
```

```
usage: vamp-iac-audit scan [-h] --path DIR
                            [--terraform] [--cloudformation] [--helm]
                            [--json FILE] [--html FILE]
```

## Examples

```bash
# Scan all IaC types in current directory (auto-detect)
vamp-iac-audit scan --path .

# Scan only Terraform files
vamp-iac-audit scan --path ./infra --terraform

# Scan only CloudFormation templates
vamp-iac-audit scan --path ./cfn --cloudformation

# Scan only Helm charts
vamp-iac-audit scan --path ./charts --helm

# Export findings to JSON and HTML
vamp-iac-audit scan --path ./infra --json results.json --html report.html

# Scan multiple types explicitly
vamp-iac-audit scan --path ./infra --terraform --cloudformation
```

## CLI Reference

| Flag | Default | Description |
|------|---------|-------------|
| `--path DIR` | required | Directory to scan recursively |
| `--terraform` | auto | Scan Terraform `.tf` and `.tfvars` files |
| `--cloudformation` | auto | Scan CloudFormation YAML/JSON templates |
| `--helm` | auto | Scan Helm chart `templates/*.yaml` files |
| `--json FILE` | — | Export results to JSON |
| `--html FILE` | — | Export dark-theme standalone HTML report |

## Output Formats

| Format | Flag | Description |
|--------|------|-------------|
| Console | (default) | Rich tables per file with color-coded findings by severity |
| JSON | `--json FILE` | Machine-readable full result set |
| HTML | `--html FILE` | Dark-theme standalone report |

## Checks Reference

### Terraform (IAC-TF-*)

| ID | Check | Severity | MITRE |
|----|-------|----------|-------|
| IAC-TF-001 | `aws_security_group` with `cidr_blocks = ["0.0.0.0/0"]` on ingress | CRITICAL | T1190 |
| IAC-TF-002 | `aws_s3_bucket` with `acl = "public-read"` or `"public-read-write"` | HIGH | T1530 |
| IAC-TF-003 | `aws_iam_policy` with `Action = "*"` or `Resource = "*"` | HIGH | T1098 |
| IAC-TF-004 | `aws_db_instance` with `publicly_accessible = true` | HIGH | T1190 |
| IAC-TF-005 | `aws_instance`/`aws_launch_template` without `encrypted` on root block device | MEDIUM | T1486 |
| IAC-TF-006 | Variable with `sensitive = false` and name containing `password`/`secret`/`key`/`token` | MEDIUM | T1552 |
| IAC-TF-007 | Hardcoded secret value pattern (`sk_`, `ghp_`, `AKIA`) | CRITICAL | T1552 |
| IAC-TF-008 | `aws_security_group` with port 22 or 3389 open to `0.0.0.0/0` | CRITICAL | T1021 |
| IAC-TF-009 | `aws_rds_cluster` without `backup_retention_period` or set to 0 | MEDIUM | T1485 |
| IAC-TF-010 | `google_compute_firewall` with `source_ranges = ["0.0.0.0/0"]` | HIGH | T1190 |

### CloudFormation (IAC-CF-*)

| ID | Check | Severity |
|----|-------|----------|
| IAC-CF-001 | SecurityGroup with `IpProtocol: "-1"` and `CidrIp: "0.0.0.0/0"` | CRITICAL |
| IAC-CF-002 | S3 with `AccessControl: PublicRead` or `PublicReadWrite` | HIGH |
| IAC-CF-003 | IAM Policy with `Action: "*"` or `Resource: "*"` | HIGH |
| IAC-CF-004 | RDS with `PubliclyAccessible: true` | HIGH |
| IAC-CF-005 | String parameter without `NoEcho: true` and name containing `password`/`secret`/`key` | MEDIUM |
| IAC-CF-006 | SecurityGroup with port 22/3389 open to `0.0.0.0/0` | CRITICAL |
| IAC-CF-007 | KMS without `EnableKeyRotation: true` | LOW |
| IAC-CF-008 | S3 without `BucketEncryption` configured | MEDIUM |

### Helm (IAC-HLM-*)

| ID | Check | Severity |
|----|-------|----------|
| IAC-HLM-001 | `securityContext.privileged: true` | CRITICAL |
| IAC-HLM-002 | `hostNetwork: true` | HIGH |
| IAC-HLM-003 | `hostPID: true` or `hostIPC: true` | HIGH |
| IAC-HLM-004 | Missing `securityContext.runAsNonRoot: true` | MEDIUM |
| IAC-HLM-005 | Missing `resources.limits` in containers | MEDIUM |
| IAC-HLM-006 | Env value with hardcoded secret pattern (`sk_`, `ghp_`, `AKIA`, `ey...`) | CRITICAL |
| IAC-HLM-007 | `serviceAccount.automountServiceAccountToken: true` (default) | LOW |
| IAC-HLM-008 | `capabilities.add` with `SYS_ADMIN`, `NET_ADMIN`, or `SYS_PTRACE` | HIGH |

## Exit Codes

| Code | Meaning | CI/CD Behavior |
|------|---------|----------------|
| `0` | No critical or high findings | Pipeline passes |
| `1` | Critical or high findings detected | Pipeline fails — review required |
| `2` | Execution error | Pipeline fails — check configuration |

## Legal Notice

Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.

## Part of VampSecure Labs Toolkit

`vamp-iac-audit` is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:

- Portfolio: [github.com/Vampsecure-Labs](https://github.com/Vampsecure-Labs)
- Orchestrator: [github.com/Vampsecure-Labs/vamp-orchestrator](https://github.com/Vampsecure-Labs/vamp-orchestrator)

---

© VampSecure Studios — VampSecure Labs Security Research Division

## Versión
v1.0 — VampSecure Labs Security Research Division
