Reunifying the Cloud: Introducing Aurelian for Multi-Cloud Security Testing
嗯,用户让我总结一下关于Aurelian的文章,控制在100字以内。首先,我需要理解文章内容。Aurelian是一个用Go语言写的开源云安全框架,支持AWS、Azure和GCP。它有25个模块,能统一进行侦察、发现秘密和IAM分析。 接下来,用户可能想知道Aurelian和其他工具比如Prowler或ScoutSuite的不同之处。文章提到Aurelian是为渗透测试人员设计的,使用实际的IAM评估逻辑,而不仅仅是检查配置标志。它还能实时验证发现的凭证,并检测特权提升路径。 另外,用户还问到Aurelian是否能检测IAM特权提升路径。答案是肯定的,它有一个模块可以分析每个主体的有效权限,并将关系图导出到Neo4j进行查询。 最后,关于如何发现暴露的云资源,Aurelian使用IAM策略评估引擎,考虑条件键、SCP和资源ARN模式,识别真正公开的资源。 总结时需要涵盖这些关键点:开源、支持多云、25个模块、渗透测试用途、实时验证、特权提升检测、关系图分析以及资源发现方法。控制在100字以内,确保信息全面且简洁。 </think> Aurelian 是一个用 Go 语言编写的开源云安全框架,支持 AWS、Azure 和 GCP 的统一侦察、秘密发现和 IAM 分析。它包含 25 个模块,使用实际 IAM 逻辑评估资源策略,并通过实时 API 验证凭证。此外,Aurelian 还能检测特权提升路径并生成关系图谱。 2026-3-20 09:25:0 Author: securityboulevard.com(查看原文) 阅读量:1 收藏

Aurelian is an open-source cloud security framework written in Go that unifies reconnaissance, secrets discovery, and IAM analysis across AWS, Azure, and GCP. It ships 25 modules, evaluates resource policies using real IAM evaluation logic, validates discovered credentials against live APIs, and maps privilege escalation paths to Neo4j. It runs as a CLI or a Go library. Aurelian is the heart of Praetorian Guard’s cloud capabilities.

Aurelian is built for penetration testers, not compliance auditors. It evaluates resource policies using actual IAM evaluation logic rather than checking configuration flags. It includes secrets discovery with live validation, privilege escalation graph analysis, and subdomain takeover detection.

Yes. The analyze-iam-permissions module evaluates every principal’s effective permissions to detect privilege escalation paths, cross-account access, and create-then-use attack patterns. The graph module exports the full relationship graph to Neo4j for Cypher-based querying of multi-hop escalation chains.

Unlike tools that check a single boolean flag, Aurelian evaluates the actual resource policy using an IAM policy evaluation engine that considers condition keys, SCPs, and resource ARN patterns. It identifies resources that are truly public even when configuration flags say otherwise.


文章来源: https://securityboulevard.com/2026/03/reunifying-the-cloud-introducing-aurelian-for-multi-cloud-security-testing/
如有侵权请联系:admin#unsafe.sh