Show HN: AWSight:按固定费用进行 AWS 安全检查,并映射到 CIS/NIST 标准

1作者: kevincloudsec4 天前
我在网络安全领域工作了 15 年,亲眼目睹了许多小团队在 AWS 安全工具的成本和维护上苦苦挣扎。如果你开启 AWS Security Hub 和 AWS Config 来跟踪 CIS 基准或 SOC 2 控制措施,那么随着账户的增长,按规则和资源计费的价格会迅速增加。 我构建了 AWSight,作为一个更简单的选择。它每天对你的 AWS 账户运行数百次安全检查,并将发现的问题映射到 CIS、NIST 和 PCI DSS 控制措施。它通过只读跨账户 IAM 角色连接,并且从不写入你的环境。 结果显示在 Grafana 仪表板中,并为每个发现的问题提供修复步骤。我选择 Grafana 是因为大多数工程师已经知道如何使用它。 如果你已经自己运行 Prowler,AWSight 基本上就是那个想法,但它是托管的:计划扫描、历史跟踪和合规性映射,无需运行基础设施。 定价是固定费率,每个账户每月 249 美元起,与资源数量无关。 演示仪表板,包含示例数据(无需注册):[https://awsight.com/demo.html](https://awsight.com/demo.html) (Grafana 面板在首次访问时可能需要几分钟才能加载。) 我是一个独立创始人,正在构建这个产品。很乐意讨论架构、具体检查,或者为什么 AWS Config 的计费如此难以预测。 [https://awsight.com](https://awsight.com)
查看原文
I spent 15 years in cybersecurity and kept seeing small teams struggle with the cost and maintenance of AWS security tooling. If you turn on AWS Security Hub and AWS Config to track CIS benchmarks or SOC 2 controls, the per-rule and per-resource pricing adds up quickly as accounts grow.<p>I built AWSight as a simpler option. It runs a few hundred security checks against your AWS accounts daily and maps findings to CIS, NIST, and PCI DSS controls. It connects through a read-only cross-account IAM role and never writes to your environment.<p>Results show up in Grafana dashboards with remediation steps for each finding. I chose Grafana because most engineers already know how to use it.<p>If you already run Prowler yourself, AWSight is basically that idea but managed: scheduled scans, historical tracking, and compliance mapping without running the infrastructure.<p>Pricing is flat-rate starting at $249&#x2F;month per account, regardless of resource count.<p>Demo dashboards with sample data (no signup): <a href="https:&#x2F;&#x2F;awsight.com&#x2F;demo.html" rel="nofollow">https:&#x2F;&#x2F;awsight.com&#x2F;demo.html</a><p>(Grafana panels can take a few moments to load on first visit.)<p>I&#x27;m a solo founder building this. Happy to talk architecture, specific checks, or why AWS Config billing is so difficult to predict.<p><a href="https:&#x2F;&#x2F;awsight.com" rel="nofollow">https:&#x2F;&#x2F;awsight.com</a>