multicloud365
  • Home
  • Cloud Architecture
    • OCI
    • GCP
    • Azure
    • AWS
    • IAC
    • Cloud Networking
    • Cloud Trends and Innovations
    • Cloud Security
    • Cloud Platforms
  • Data Management
  • DevOps and Automation
    • Tutorials and How-Tos
  • Case Studies and Industry Insights
    • AI and Machine Learning in the Cloud
No Result
View All Result
  • Home
  • Cloud Architecture
    • OCI
    • GCP
    • Azure
    • AWS
    • IAC
    • Cloud Networking
    • Cloud Trends and Innovations
    • Cloud Security
    • Cloud Platforms
  • Data Management
  • DevOps and Automation
    • Tutorials and How-Tos
  • Case Studies and Industry Insights
    • AI and Machine Learning in the Cloud
No Result
View All Result
multicloud365
No Result
View All Result

YES3 Scanner: Open-source S3 safety scanner for public entry, ransomware safety

admin by admin
April 9, 2025
in Cloud Security
0
YES3 Scanner: Open-source S3 safety scanner for public entry, ransomware safety
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


YES3 Scanner is an open-source software that scans and analyzes 10+ totally different configuration gadgets to your S3 buckets in AWS. This contains entry comparable to public entry through ACLs and bucket insurance policies – together with the complicated mixtures of account and bucket settings that may make a S3 bucket successfully public.

S3 security scanner

“We constructed this software after realizing potential customers wanted a greater technique to scan their S3 assets for entry and ransomware safety. We needed to have a software that not solely scans for entry points with S3, but in addition checks for added layers of safety together with serving to to stop in opposition to ransomware,” Jason Kao, Founding father of Fog Safety, instructed Assist Web Safety.

When evaluating the present panorama of each paid and free instruments for assessing S3 safety, Kao and his staff discovered important gaps. “We observed points with current instruments and even safety and compliance frameworks, together with false negatives, false positives, deceptive and incomplete outcomes,” he stated.

Compounding the problem, AWS has launched options like default encryption, Block Public Entry, and the flexibility to disable ACLs lately. Whereas these enhancements supply extra layers of safety, Kao famous they will additionally complicate efforts to know a corporation’s true knowledge safety posture in AWS.

That complexity is precisely what the YES3 Scanner goals to sort out. “The individuality of YES3 Scanner comes from our understanding of how the totally different S3 configuration gadgets work with one another,” Kao defined. He added that many instruments out there fall quick by providing solely a partial image. “Safety requires a complete and full understanding of all related configuration gadgets,” he stated. “That’s why we developed YES3.”

YES3 Scanner checks for the next S3 configuration gadgets:

  • Bucket Entry Management Lists (ACLs)
  • Bucket Coverage (Useful resource-Primarily based Coverage)
  • Bucket Web site Settings
  • Account Public Entry Block
  • Bucket Public Entry Block
  • Disabled ACLs (through Possession Controls)
  • Bucket Encryption Settings
  • Object Lock Configuration
  • Bucket Versioning Settings
  • Bucket Lifecycle Configuration

Future plans and obtain

“Our future plans are to incorporate extra evaluation on S3 and cloud configuration comparable to logging to assist present holistic safety in opposition to entry and ransomware within the cloud. We additionally plan to take heed to what customers request to see how we are able to improve the software for his or her use instances. Moreover, we plan on constructing extra detailed layers of safety – together with each on the multi-account (organizational) degree and on the object/knowledge degree in S3,” Kao defined.

YES3 Scanner is obtainable at no cost on GitHub. Extra data is on this weblog.

Should learn:


Subscribe to the Assist Web Safety ad-free month-to-month e-newsletter to remain knowledgeable on the important open-source cybersecurity instruments. Subscribe right here!

Tags: accessOpensourceProtectionPublicRansomwareScannerSecurityYES3
Previous Post

Methods to monetize an API on AWS?

Next Post

Serverless vs. Simply-in-Time Compute: Are They the Similar?

Next Post
Serverless vs. Simply-in-Time Compute: Are They the Similar?

Serverless vs. Simply-in-Time Compute: Are They the Similar?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending

Azure Databricks Pricing Defined

Azure Databricks Pricing Defined

April 8, 2025
Anyscale powers AI compute for any workload utilizing Google Compute Engine

Anyscale powers AI compute for any workload utilizing Google Compute Engine

March 26, 2025
Unlock the ability of Ncrack community authentication cracking!

Unlock the ability of Ncrack community authentication cracking!

May 14, 2025
ManagedMethods Launches Classroom Supervisor | Within the Information

ManagedMethods Launches Classroom Supervisor | Within the Information

April 9, 2025
Clouds Shift From Riches To RAGs

Clouds Shift From Riches To RAGs

March 29, 2025
Cloud-Based mostly Blockchain To Improve Effectivity and Scalability

The 2025 ERP Implementation Playbook

April 17, 2025

MultiCloud365

Welcome to MultiCloud365 — your go-to resource for all things cloud! Our mission is to empower IT professionals, developers, and businesses with the knowledge and tools to navigate the ever-evolving landscape of cloud technology.

Category

  • AI and Machine Learning in the Cloud
  • AWS
  • Azure
  • Case Studies and Industry Insights
  • Cloud Architecture
  • Cloud Networking
  • Cloud Platforms
  • Cloud Security
  • Cloud Trends and Innovations
  • Data Management
  • DevOps and Automation
  • GCP
  • IAC
  • OCI

Recent News

Closing the cloud safety hole with runtime safety

Closing the cloud safety hole with runtime safety

May 20, 2025
AI Studio to Cloud Run and Cloud Run MCP server

AI Studio to Cloud Run and Cloud Run MCP server

May 20, 2025
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact

© 2025- https://multicloud365.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Cloud Architecture
    • OCI
    • GCP
    • Azure
    • AWS
    • IAC
    • Cloud Networking
    • Cloud Trends and Innovations
    • Cloud Security
    • Cloud Platforms
  • Data Management
  • DevOps and Automation
    • Tutorials and How-Tos
  • Case Studies and Industry Insights
    • AI and Machine Learning in the Cloud

© 2025- https://multicloud365.com/ - All Rights Reserved