Scout Suite: multi-cloud configuration auditing

Scout Suite · GPL-2.0

Scout Suite collects configuration from a cloud account through its APIs and produces a navigable HTML report with findings grouped by service. Where Prowler gives you a stream of check results, Scout Suite gives you a browsable model of the account.

Install

pipx install scoutsuite
# or
git clone https://github.com/nccgroup/ScoutSuite && cd ScoutSuite
pip install -r requirements.txt && python scout.py --help

Core commands

# AWS with a named profile
scout aws --profile client-audit

# restrict services and regions
scout aws --profile client-audit --services s3,iam,ec2 --regions us-east-1

# Azure
scout azure --cli

# GCP
scout gcp --user-account --project-id <id>

# output location
scout aws --profile client-audit --report-dir ./scout-report --no-browser

Output

An HTML report plus the underlying JSON in scoutsuite-results/. The JSON is what you parse; the HTML is what you use while testing.

Where it sits in Tandera

Scout Suite runs in the static phase of recon_cloud, alongside prowler. Both need the same authenticated access.

Running both is the same reasoning as the three subdomain producers: different check sets, different blind spots. Prowler’s strength is breadth of individual checks and compliance mapping; Scout Suite’s is showing how resources relate — which role can assume which, what a security group actually exposes. Tandera merges and deduplicates the findings so the client does not see the same misconfiguration twice under two tool names.

Using it in a pentest

Use the HTML while testing, the JSON for the report. The browsable view is genuinely good for understanding an unfamiliar account quickly. Do not paste its screenshots into the deliverable as findings.

IAM is where the real findings are. Public storage is easy and everyone checks it. Over-permissive roles, trust policies that allow assumption from unexpected principals, and unused credentials with high privilege are harder to spot and matter more.

Note the collection timestamp. Cloud configuration changes daily. A finding is a statement about the account at a moment; date it, or the client will dispute it after their next deploy.

early access

Get Tandera before your next engagement.

Join the waitlist for early access. We are onboarding pentest teams in waves.

Priority onboarding for pentest teams.
A direct line to the people building it.
Early-access pricing, locked in.

No spam, no card. Unsubscribe anytime.

enespt-br