About this project

OpenShield is designed as an accessible, low-cost alternative to commercial CSPM platforms that often charge tens to hundreds of thousands of dollars annually, serving startups, small and medium enterprises, academic teams, and student groups that lack visibility into their Azure cloud security posture. Core capabilities include a misconfiguration scanner running 144 Azure security rules across storage, network, identity, database, compute, Key Vault, AKS and Kubernetes workloads, backup, serverless, private endpoint, and supply chain posture. It also includes dedicated post-quantum cryptography scanning to identify classical RSA, ECC, TLS, and certificate assets vulnerable to Harvest Now Decrypt Later attacks, with findings mapped to NIST FIPS 203, 204, and 205 standards to support quantum-safe migration planning. The tool automatically maps scan findings to CIS Benchmarks, NIST CSF, ISO 27001, and SOC 2 framework definitions, with compliance reports representing evidence coverage rather than formal third-party certification. Every documented scan rule is paired with a review-gated Azure CLI remediation playbook (144 total) to enable one-command fixes for identified issues. Scan results and findings are stored in PostgreSQL, with a Flask REST API exposing endpoints for findings, security scores, scan history, compliance posture, drift detection, and resource inventory. The API enforces JWT authentication for write endpoints, and fails startup in production environments if JWT secrets are missing, set to insecure defaults, or shorter than 32 characters. A React-based security dashboard provides live monitoring, prioritized findings, compliance tracking, drift visibility, and AI-layer views. A dedicated project website hosts documentation, rule galleries, architecture guides, evidence resources, roadmap updates, and a learning portal for new users. Findings can be normalized and pushed to Microsoft Sentinel via Log Analytics custom tables and KQL analytics rules for centralized SIEM alerting. The project holds an OpenSSF Best Practices Passing badge, with release artifacts including SHA-256 checksums, SBOMs, and identity-bound provenance attestations for user verification. It uses a maintainer-led collaborative governance model, is licensed under MIT, and supports local development deployment via Docker Compose. Planned roadmap items include multi-cloud support for AWS and GCP.