57 Findings Across 12 AWS Services. Zero False Positives. No Credentials Required.
✓ Human-authored analysis; AI used for formatting and proofreading. NCC Group built SadCloud to test cloud security tools. It deploys intentionally vulnerable AWS infrastructure with 84 misconfigurations across 22 services so you can measure exactly what your scanner catches and what it misses. We pointed a static analyzer at a SadCloud deployment. It does not use credentials or make API calls…
NCC Group developed a tool called SadCloud to evaluate cloud security tools by deploying intentionally vulnerable AWS infrastructure with 84 misconfigurations across 22 services. Using a static analyzer, 57 findings were identified across 12 AWS services without requiring any credentials or API calls against the live environment.
The analyzer found 57 issues in four iterations, each time fixing identified gaps. The findings are categorized into critical, high, medium, and low/Info severity. The most significant finding is a chain of events where CloudWatch detection is broken, specifically the detection pipeline being broken at the metric-filter, alarm, or alarm-action layer, rendering any monitoring ineffective.
This blind spot is not typically detected by individual-check scanners, highlighting the importance of evaluating the composition of security measures rather than just their individual settings.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.