AWSHound — An OpenSource AWS OpenGraph Collector
Tools2026-08-27, 11:01
AWSHound helps identify multi-step attack paths between users, roles, and resources.
Key features:
• Access assessment — AWSHound calculates effective permissions, taking applicable policies and restrictions into account
• Cross-account analysis — collects data from the entire AWS Organization and shows paths between accounts
• Offline analysis — allows saved data to be reprocessed without access to AWS
• BloodHound integration — after the graph is loaded, built-in pathfinding and Cypher queries are available in Community Edition and Enterprise Edition
Context-dependent conditions cannot be fully evaluated offline, so some paths are hypothetical and require manual verification. AWSHound’s KMS collection is currently limited to same-account relationships.
Vendors
Products