About

One practitioner, one honest scanner.

Plexavo is built and maintained by Kavee, a cloud security practitioner and security researcher. It exists because most small teams run everything on the cloud with nobody whose job is to watch it.

Kavee

I work in cloud and identity security, across AWS, Azure and GCP, and on Active Directory and hybrid identity. My day to day is a mix of hands-on security assessments, privilege-escalation and misconfiguration research, and reading a lot of policy documents so other people do not have to.

Most of the accounts I look at were not set up carelessly. They were set up by people with a product to ship and no security specialist on the team, and the defaults quietly added up. Plexavo is the tool I wanted to be able to hand those teams: something that finds the real problems, explains what an attacker would do with each one, and gives the exact fix.

It is open source on purpose. If a scanner tells you your account is fine, you should be able to read the check that decided that.

Focus areas
Cloud
AWS, Azure, GCP: IAM and RBAC, privilege escalation, exposed storage and network, logging and detection gaps.
Identity
Active Directory, Entra ID, hybrid identity, trust relationships and delegation.
Research
Misconfiguration patterns, attack-path analysis, turning findings into plain-English remediation.

How Plexavo is run.

Open source, AGPL-3.0

The detection logic is the repo, not a thin client around a closed API. Read it, run it, send a PR.

Zero telemetry

Nothing about your account or your scans is ever sent anywhere. It runs on your own credentials, locally.

Tested in the open

Every check has a published test matrix, and anyone who finds a genuine miss gets credited in the Hall of Bugs.

Get in touch

Questions, a missed finding, or an AWS account you want a second pair of eyes on. All of it is welcome.