Ad

SkyArk: Discover privileged entities in Azure & AWS

SkyArk helps organizations discover, assess, and secure privileged entities in Azure and AWS environments to mitigate the risk of cloud shadow admins.
Screenshot of cyberark/SkyArk homepage

SkyArk helps organizations discover, assess, and protect privileged entities in their cloud environments. SkyArk features two main scanning modules, AzureStealth and AWStealth, designed to identify and analyze users, groups, and roles with potentially excessive permissions. This project addresses the growing threat of cloud shadow admins, a tactic where unauthorized users gain elevated privileges, enabling them to escalate their access and potentially compromise the entire cloud environment.

SkyArk was initially developed to address the shadow admin threat in AWS, building upon research presented at RSA USA 2018. It later expanded to include AzureStealth, providing similar capabilities for Azure environments. These tools help security teams proactively identify and mitigate risks associated with privileged access.

SkyArk offers open-source tools for discovering privileged entities in both AWS and Azure, facilitating proactive security assessments. It provides targeted detection of cloud shadow admins, a critical vulnerability for organizations. Furthermore, SkyArk includes a module for analyzing AWS CloudTrail logs, enabling deeper insights into user activity. The tools are designed for easy deployment with minimal permissions, streamlining the scanning process.

  • Core Functionality: Scans for privileged entities (users, groups, roles) in AWS and Azure environments.
  • Platform Support: Supports both Amazon Web Services (AWS) and Microsoft Azure.
  • Shadow Admin Detection: Specifically identifies potentially unauthorized privileged users (shadow admins).
  • CloudTrail Analysis: Includes AWStrace module for analyzing AWS CloudTrail logs and identifying risky actions.
  • Easy Deployment: Requires read-only permissions for scanning and can be run from the command line or Azure Portal CloudShell.
  • Extensible: Includes auxiliary modules like AWStrace for expanded analysis capabilities.
  • Developer Experience: Provides clear READMEs with detailed instructions and demos.

SkyArk is an active project with ongoing development and maintenance. It has a significant number of stars and forks on GitHub, indicating community interest and usage. Regular updates and recent commits suggest continued active development. Comprehensive documentation is available for both AzureStealth and AWStealth, supporting proper usage and integration. The project has been presented at industry conferences, further highlighting its relevance and value.

SkyArk is beneficial for security professionals responsible for cloud security posture management and risk assessment. It addresses the critical need to identify and mitigate the risk of cloud shadow admins, helping organizations to protect their cloud environments from unauthorized access and privilege escalation. It offers a valuable alternative to manual privilege assessments and provides insights into potential security vulnerabilities.

Summarize:
Share:
Stars
912
Forks
163
Issues
6
Created
8 years ago
Commit
1 year ago
License
MIT
Archived
No
Updated 2 days ago

Similar Repositories