
Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with one command
Open source Cloud Security Posture Management (CSPM) for Azure detect misconfigurations, map them to CIS / NIST / ISO 27001 / SOC 2, remediate with one command, and identify cryptographic assets requiring quantum-safe migration.
Website · Documentation · Roadmap · Changelog · Security Policy · Discord
Release artifacts include SHA-256 checksums, an SBOM, and identity-bound provenance attestations. See release verification.
OpenShield is led through a collaborative, maintainer-led governance model.
| Name | Role | Responsibilities |
|---|---|---|
| Vishnu Ajith | Project Lead | Project direction, final governance decisions, releases, and organization administration |
| Muhammad Ibrahim | Co-Project Lead | Engineering direction, security and enterprise-readiness, contributor coordination, and project delivery |
| Muhammad Sihan Haroon | Co-Project Lead | Technical leadership, contributor coordination, and project delivery |
The complete leadership and maintainer responsibilities are recorded in MAINTAINERS.md and governed by GOVERNANCE.md.
Enterprise cloud security tools like Wiz, Prisma Cloud, and Microsoft Defender for Cloud cost $50,000–$500,000/year.
Startups, SMEs, universities, and student teams are left with zero visibility into their Azure security posture. A misconfigured storage blob, an overprivileged service principal, or an open NSG rule can sit undetected for months.
OpenShield changes that.
Adversaries are collecting encrypted Azure traffic today to decrypt it when quantum computers become available. This is called a Harvest Now Decrypt Later attack and it is happening right now.
OpenShield scans Azure for classical cryptographic assets that need migration before it is too late:
Findings map to NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) and feed directly into post-quantum migration planning.
| Feature | Description |
|---|---|
| Misconfiguration Scanner | Runs 95 Azure security rules across storage, network, identity, database, compute, Key Vault, AKS, Kubernetes workloads, post-quantum cryptography, backup, serverless, private endpoint, and supply chain posture |
| Compliance Mapper | Maps findings to CIS Benchmarks, NIST CSF, ISO 27001, and SOC 2 framework JSON files |
| Scan History API | Stores scans and findings in PostgreSQL and exposes findings, score, scan history, compliance posture, drift, and resource inventory over REST |
| Remediation Playbooks | Every documented rule ships with a matching review-gated remediation script (95 playbooks) |
| Security Dashboard | Full React dashboard deployed on Vercel - live monitoring, findings, compliance, drift, prioritization, and AI-layer views |
| Project Website | Documentation and reference site at owasp.github.io/openshield - blog, rules gallery, architecture, evidence guides, roadmap, and releases |
| Sentinel Integration | Normalises findings and pushes them into Microsoft Sentinel via a Log Analytics custom table and KQL analytics rules |
OpenShield has achieved the OpenSSF Best Practices Passing Badge, completing 100% of the applicable Passing-level criteria across project governance, change control, reporting, quality, security, and code analysis.
OpenSSF Best Practices - Passing
The project's OpenSSF status is publicly verifiable through the official OpenSSF Best Practices project record. OpenShield continues to strengthen its engineering, security assurance, and open source governance practices as it progresses through the higher-level criteria.
View OpenShield's verified OpenSSF Best Practices record
Project policies and assurance evidence: