AWS security report orchestrator
SentryHive
Point it at a client's AWS account and get an evidence-grade security report from best-in-class open-source scanners — no manual tool wrangling. Built for security consultants and auditors. It merges output from every scanner into one consolidated report — branded HTML, Markdown, and JSON — instead of reconciling four different tool formats by hand. Cross-account scanning is the default: assume a read-only role into as many client accounts as an engagement needs, and get a per-account report plus a roll-up summary.
Highlights
- Cross-account by default — assume-role into many client accounts, get per-account reports plus a roll-up
- Read-only, least-privilege IAM shipped alongside — no write access required
- Branded HTML + Markdown + JSON output, ready to hand a client as a deliverable
- Single Docker image — no four-toolchain install to manage
Bundled tools
Prowler
core500+ checks mapped to CIS, PCI-DSS, SOC 2, ISO 27001, HIPAA, and NIST 800-53.
Cloudsplaining
coreIAM policy risk — over-privilege, privilege escalation, and public exposure.
hardeneks
auto-detectedEKS best-practice checks, triggered automatically when the account runs EKS.
ASH
opt-inStatic analysis of local code and IaC — Terraform, CloudFormation, and secrets.
SentryHive is free and open source — clone it, run it, or contribute.
github.com/d2k-klin/sentryhive