BreakMesh – Vulnerability Simulator & Cyber Range

Scanner package

Cloud Posture (CSPM) scanner

Read-only cloud configuration checks across AWS, Azure, and GCP — list/describe/get calls only, never writes or deletes.

What it checks

On AWS: public S3 storage exposure, open security-group ingress, stale IAM access keys, overly-permissive IAM policies, disabled CloudTrail logging, and default-encryption gaps.

On Azure: public blob storage exposure and open NSG ingress rules. On GCP: public cloud storage exposure and open VPC firewall ingress.

Credentials used once, never stored

Provide read-only credentials for whichever provider(s) you want scanned — leave any provider's fields blank to skip it. Credentials are used only for the duration of the scan and are never written to disk or the database.

All 10 checks in this package

Included from the Team plan and up.

  • AWS Public S3 Storage Exposure
  • AWS Open Security Group Ingress
  • AWS IAM Stale Access Keys
  • AWS Overly-Permissive IAM Policies
  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • Azure Public Blob Storage Exposure
  • Azure Open NSG Ingress Rules
  • GCP Public Cloud Storage Exposure
  • GCP Open VPC Firewall Ingress