Aurelian: from AWS configuration auditing to multi-cloud exposure detection

Aurelian has widened from AWS configuration auditing into genuine multi-cloud exposure detection. It now sweeps Azure for publicly reachable resources through Resource Graph queries, continues to catch the AWS misconfigurations that lead to credential theft, and scans AWS secrets incrementally so repeat runs no longer re-examine everything that has not changed.
What's New
New: Azure public resource detection
- Publicly reachable resources across the subscription — Aurelian's Azure reconnaissance uses Azure Resource Graph queries to find exposed storage, networking, database, and application-layer resources, and surfaces confirmed exposures as findings. Covered today: Storage containers configured for public blob or container access, standalone public IP resources, load balancers with public frontend configurations, Azure SQL instances reachable from the internet, Network Security Groups with overly permissive inbound rules, and App Service resources without access restrictions.
- Structured output — detections are emitted as
CloudResourceobjects carrying public-access properties, withRiskobjects raised for confirmed exposures, so Azure exposure lands in the same model as the rest of Guard's cloud data.
AWS configuration auditing
- EC2 IMDSv1 detection — instances left on IMDSv1 (
HttpTokens=optional) are open to SSRF-based IAM credential theft, a well-travelled cloud attack path. Aurelian enumerates EC2 instances across the account and emits a Medium-severity risk for each instance that still permits IMDSv1, surfaced in the Guard vulnerability view alongside other cloud posture issues.
Faster, broader AWS secret scanning
- Checkpoint-based incremental scans — the last successful scan checkpoint is passed to Aurelian and persisted only after a fully successful run (with a one-minute overlap), so unchanged AWS resources are not re-scanned on every pass.
- Full ECS task definition scanning — the complete ECS task definition is now forwarded to the secret scanner, bringing environment variables and configuration embedded in task definitions into scope.
- Resource Access Manager share enumeration — the list-all reconnaissance path now enumerates AWS RAM resource shares, recording principals, shared resources, and whether
AllowExternalPrincipalsis set, so cross-account sharing is visible rather than assumed.