There are 53 repositories under cloud-security topic.
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
Free Security and Hacking eBooks
🛡️ Awesome Cloud Security Resources ⚔️
Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
awesome cloud security 收集一些国内外不错的云安全资源,该项目主要面向国内的安全人员
An encyclopedia for offensive and defensive security knowledge in cloud native technologies.
veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security
The easiest way to access your cloud.
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
Constellation is the first Confidential Kubernetes. Constellation shields entire Kubernetes clusters from the (cloud) infrastructure using confidential computing.
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks
Awesome cloud enumerator
A Huge Learning Resources with Labs For Offensive Security Players
Security Remediation Guides
A curated list of awesome cloud security blogs, podcasts, standards, projects, and examples.
TerraformGoat is HXSecurity research lab's "Vulnerable by Design" multi cloud deployment tool.
文章 Attack Code 的详细全文。安全和开发总是具有伴生属性,尤其是云的安全方向,本篇文章是希望能帮助到读者的云安全入门材料。Full text of the article Attack Code. Security and development always have concomitant attributes, and this is especially true with the security direction of the cloud. This article is an introduction to cloud security that I hope will help readers.
BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text.
AWS云平台 AccessKey 泄漏利用工具
MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).
旨在以攻促防,针对Docker TCP socket的开源利用工具
cloudgrep is grep for cloud storage