Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
openshield — Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with one command | Kitploit
工具/GitHubGitHub/owasp/openshield
Vulnerability ScannersConfiguration AuditingCryptographyCloud SecurityDevSecOpsThreat IntelligenceMisconfiguration
GitHubowasp/openshield

openshield

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with one command

查看仓库
5769716天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。
OpenShield

Open source Cloud Security Posture Management (CSPM) for Azure detect misconfigurations, map them to CIS / NIST / ISO 27001 / SOC 2, remediate with one command, and identify cryptographic assets requiring quantum-safe migration.

Website · Documentation · Roadmap · Changelog · Security Policy · Discord

OpenSSF Best Practices OpenShield CI CodeQL Deploy OWASP

License: MIT Python 3.11 GitHub Repo stars GitHub contributors GitHub last commit GitHub issues PRs Welcome Discord

Release artifacts include SHA-256 checksums, an SBOM, and identity-bound provenance attestations. See release verification.


Project Leadership

OpenShield is led through a collaborative, maintainer-led governance model.

NameRoleResponsibilities
Vishnu AjithProject LeadProject direction, final governance decisions, releases, and organization administration
Muhammad IbrahimCo-Project LeadEngineering direction, security and enterprise-readiness, contributor coordination, and project delivery
Muhammad Sihan HaroonCo-Project LeadTechnical leadership, contributor coordination, and project delivery

The complete leadership and maintainer responsibilities are recorded in MAINTAINERS.md and governed by GOVERNANCE.md.


The Problem

Enterprise cloud security tools like Wiz, Prisma Cloud, and Microsoft Defender for Cloud cost $50,000–$500,000/year.

Startups, SMEs, universities, and student teams are left with zero visibility into their Azure security posture. A misconfigured storage blob, an overprivileged service principal, or an open NSG rule can sit undetected for months.

OpenShield changes that.

Why Post-Quantum Cryptography Matters Now

Adversaries are collecting encrypted Azure traffic today to decrypt it when quantum computers become available. This is called a Harvest Now Decrypt Later attack and it is happening right now.

OpenShield scans Azure for classical cryptographic assets that need migration before it is too late:

  • TLS configurations using RSA or ECDH key exchange on App Services
  • Key Vault keys using RSA or ECC algorithms vulnerable to Shor's algorithm
  • Certificates using classical signature algorithms

Findings map to NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) and feed directly into post-quantum migration planning.


What OpenShield Does

FeatureDescription
Misconfiguration ScannerRuns 95 Azure security rules across storage, network, identity, database, compute, Key Vault, AKS, Kubernetes workloads, post-quantum cryptography, backup, serverless, private endpoint, and supply chain posture
Compliance MapperMaps findings to CIS Benchmarks, NIST CSF, ISO 27001, and SOC 2 framework JSON files
Scan History APIStores scans and findings in PostgreSQL and exposes findings, score, scan history, compliance posture, drift, and resource inventory over REST
Remediation PlaybooksEvery documented rule ships with a matching review-gated remediation script (95 playbooks)
Security DashboardFull React dashboard deployed on Vercel - live monitoring, findings, compliance, drift, prioritization, and AI-layer views
Project WebsiteDocumentation and reference site at owasp.github.io/openshield - blog, rules gallery, architecture, evidence guides, roadmap, and releases
Sentinel IntegrationNormalises findings and pushes them into Microsoft Sentinel via a Log Analytics custom table and KQL analytics rules

Security Assurance

OpenShield has achieved the OpenSSF Best Practices Passing Badge, completing 100% of the applicable Passing-level criteria across project governance, change control, reporting, quality, security, and code analysis.

OpenSSF Best Practices Passing Badge

OpenSSF Best Practices - Passing

The project's OpenSSF status is publicly verifiable through the official OpenSSF Best Practices project record. OpenShield continues to strengthen its engineering, security assurance, and open source governance practices as it progresses through the higher-level criteria.

View OpenShield's verified OpenSSF Best Practices record

Project policies and assurance evidence:

下载工具