Introduction
Welcome to Documentation of SCCCE.
Overview
What is SCCCE?
SCCCE stands for Security Compliance Checker for Cloud Environments. It aims to reduce the manual work & act as a tool to help auditors to audit the cloud environment
Why we need SCCCE?
Existing Cloud Config Review Workflow is complicated and requires manual work. Two main problems with this is error prone and time consuming. With SCCCE, we aim to automate the process of reviewing the cloud environment and provide a more efficient way to audit the cloud environment.
Expected Functionalities
SCCCE is a tool that helps you to scan your cloud environment for vulnerabilities and misconfigurations.
Hopefully, SCCCE can provide the following functionalities:
- List all infrastructure information
- Scan for vulnerabilities and misconfigurations
- Provide additional tools for scanning and reporting
- Ability to enable log monitoring and analysis
- Logs collected from cloud provider
- Logs parsed to ECS format
- Logs stored in ElasticSearch
- Logs visualized in Kibana
- Logs monitored for anomalies
- Ability to enable alerting (TBD)
- Alerts on anomalies
- Alerts on misconfigurations
- Alerts on vulnerabilities