awesome-cloud-security

Cloud Security Toolkit

A curated collection of cloud security resources and tools for assessing and securing cloud environments.

🛡️ Awesome Cloud Security Resources ⚔️

GitHub

2k stars
44 watching
319 forks
last commit: almost 2 years ago
Linked from 1 awesome list

awsaws-securityazureazure-securitycloud-computingcloud-securitycybersecuritygcpgcp-securitysecurity

Standards / Compliances

CSA STAR
ISO/IEC 27017:2015
ISO/IEC 27018:2019
MTCS SS 584

Standards / Benchmarks

CIS Benchmark

Tools / Infrastructure

aws_pwn1,174about 3 years ago: A collection of AWS penetration testing junk
aws_ir344about 5 years ago: Python installable command line utility for mitigation of instance and key compromises
aws-firewall-factory237almost 2 years ago: Deploy, update, and stage your WAFs while managing them centrally via FMS
aws-vault8,554about 2 years ago: A vault for securely storing and accessing AWS credentials in development environments
awspx924almost 4 years ago: A graph-based tool for visualizing effective access and resource relationships within AWS
azucar565almost 4 years ago: A security auditing tool for Azure environments
checkov7,214almost 2 years ago: A static code analysis tool for infrastructure-as-code
cloud-forensics-utils467almost 2 years ago: A python lib for DF & IR on the cloud
Cloud-Katana250over 2 years ago: Automate the execution of simulation steps in multi-cloud and hybrid cloud environments
cloudlist871almost 2 years ago: Listing Assets from multiple Cloud Providers
Cloud Sniper182over 2 years ago: A platform designed to manage Cloud Security Operations
Cloudmapper6,017about 2 years ago: Analyze your AWS environments
Cloudmarker219about 2 years ago: A cloud monitoring tool and framework
Cloudsploit3,372almost 2 years ago: Cloud security configuration checks
CloudQuery5,913almost 2 years ago: Open source cloud asset inventory with set of pre-baked SQL for security and compliance
Cloud-custodian5,488almost 2 years ago: Rules engine for cloud security, cost optimization, and governance
consoleme3,153about 2 years ago: A Central Control Plane for AWS Permissions and Access
cs suite1,145almost 4 years ago: Tool for auditing the security posture of AWS/GCP/Azure
Deepfence ThreatMapper4,861almost 2 years ago: Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless
dftimewolf299almost 2 years ago: A multi-cloud framework for orchestrating forensic collection, processing and data export
diffy635over 2 years ago: Diffy is a digital forensics and incident response (DFIR) tool developed by Netflix
ElectricEye966almost 2 years ago: Continuously monitor AWS services for configurations
Forseti security1,276over 3 years ago: GCP inventory monitoring and policy enforcement tool
Hammer437about 3 years ago: A multi-account cloud security tool for AWS. It identifies misconfigurations and insecure data exposures within most popular AWS resources
kics2,117almost 2 years ago: Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code
Matano1,482about 2 years ago: Open source serverless security lake platform on AWS that lets you ingest, store, and analyze data into an Apache Iceberg data lake and run realtime Python detections as code
Metabadger141over 2 years ago: Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2)
Open policy agent: Policy-based control tool
pacbot1,290almost 4 years ago: Policy as Code Bot
pacu4,422almost 2 years ago: The AWS exploitation framework
PMapper1,436about 2 years ago: A tool for quickly evaluating IAM permissions in AWS
Prowler10,941almost 2 years ago: Command line tool for AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool
ScoutSuite6,794almost 2 years ago: Multi-cloud security auditing tool
Security Monkey4,353over 5 years ago: Monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time
SkyWrapper104over 5 years ago: Tool helps to discover suspicious creation forms and uses of temporary tokens in AWS
Smogcloud332about 6 years ago: Find cloud assets that no one wants exposed
Steampipe7,053almost 2 years ago: A Postgres FDW that maps APIs to SQL, plus suites of and for AWS/Azure/GCP and many others
Terrascan4,779almost 2 years ago: Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure
tfsec6,734almost 2 years ago: Static analysis powered security scanner for Terraform code
Zeus708over 6 years ago: AWS Auditing & Hardening Tool

Tools / Container

auditkube113almost 2 years ago: Audit for for EKS, AKS and GKE for HIPAA/PCI/SOC2 compliance and cloud security
Falco7,460almost 2 years ago: Container runtime security
mkit402about 5 years ago: Managed kubernetes inspection tool
Open policy agent: Policy-based control tool

Tools / SaaS

aws-allowlister224about 3 years ago: Automatically compile an AWS Service Control Policy with your preferred compliance frameworks
binaryalert1,415almost 3 years ago: Serverless S3 yara scanner
cloudsplaining2,009almost 2 years ago: An AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report
Cloud Guardrails183almost 3 years ago: Rapidly cherry-pick cloud security guardrails by generating Terraform files that create Azure Policy Initiatives
Function Shield39almost 7 years ago: Protection/destection lib of aws lambda and gcp function
FestIN231almost 6 years ago: S3 bucket finder and content discover
GCPBucketBrute494over 3 years ago: A script to enumerate Google Storage buckets
IAM Zero249over 3 years ago: Detects identity and access management issues and automatically suggests least-privilege policies
Lambda Guard400about 4 years ago: AWS Lambda auditing tool
Policy Sentry2,028almost 2 years ago: IAM Least Privilege Policy Generator
S3 Inspector: Tool to check AWS S3 bucket permissions
Serverless Goat320about 2 years ago: A serverless application demonstrating common serverless security flaws
SkyArk877almost 4 years ago: Tool to helps to discover, assess and secure the most privileged entities in Azure and AWS

Tools / Penetration testing/learning

AWSGoat1,760almost 2 years ago: AWSGoat is a vulnerable by design AWS infrastructure featuring OWASP Top 10 web application security risks (2021) and AWS service based misconfigurations
ccat595almost 7 years ago: Cloud Container Attack Tool
CloudBrute913about 2 years ago: A multiple cloud enumerator
cloudgoat2,991almost 2 years ago: "Vulnerable by Design" AWS deployment tool
Leonidas535almost 2 years ago: A framework for executing attacker actions in the cloud
Pwned Labs: Free hosted labs for learning cloud security
Sadcloud666almost 3 years ago: Tool for spinning up insecure AWS infrastructure with Terraform
TerraGoat1,159about 2 years ago: Bridgecrew's "Vulnerable by Design" Terraform repository
WrongSecrets1,246almost 2 years ago: A vulnerable app which demonstrates how to not use secrets. With AWS/Azure/GCP support

Tools / Native tools / AWS

Artifact: Compliance report selfservice
Audit manager: Continuously audit for AWS usage
Certificate Manager: Private CA and certificate management service
CloudTrail: Record and log API call on AWS
Config: Configuration and resources relationship monitoring
Elastic Disaster Recovery: Application recovery service
Detective: Analyze and visualize security data and help security investigations
Firewall Manager: Firewall management service
GuardDuty: IDS service
CloudHSM: HSM service
Inspector: Vulnerability discover and assessment service
KMS: KMS service
Macie: Fully managed data security and data privacy service for S3
Network Firewall: Network firewall service
Secret Manager: Credential management service
Security Hub: Integration service for other AWS and third-party security service
Shield: DDoS protection service
Single Sign-On: Service of centrally manage access AWS or application
ThreatMapper4,861almost 2 years ago: Identify vulnerabilities in running containers, images, hosts and repositories
VPC Flowlog: Log of network traffic
WAF: Web application firewall service

Tools / Native tools / Azure

Application Gateway: L7 load balancer with optional WAF function
DDoS Protection: DDoS protection service
Dedicated HSM: HSM service
Key Vault: KMS service
Monitor: API log and monitoring related service
Security Center: Integration service for other Azure and third-party security service
Sentinel: SIEM service

Tools / Native tools / GCP

Access Transparency: Transparency log and control of GCP
Apigee Sense: API security monitoring, detection, mitigation
Armor: DDoS protection and WAF service
Asset Inventory: Asset monitoring service
Assured workloads: Secure and compliant workloads
Audit Logs: API logs
Binanry Authorization: Binary authorization service for containers and serverless
Cloud HSM: HSM service
Cloud IDS: IDS service
Confidential VM: Encrypt data in use with VM
Context-aware Access: Enable zero trust access to applications and infrastructure
DLP: DLP service:
EKM: External key management service
Identity-Aware Proxy: Identity-Aware Proxy for protect the internal service
KMS: KMS service
Policy Intelligence: Detect the policy related risk
Security Command Center: Integration service for other GCP security service
Security Scanner: Application security scanner for GAE, GCE, GKE
Shielded VM: VM with secure boot and vTPM
Event Threat Detection: Threat dection service
VPC Service Controls: GCP service security perimeter control

Reading Materials / AWS

Overiew of AWS Security
AWS-IAM-Privilege-Escalation by RhinoSecurityLabs901about 7 years ago: A centralized source of all AWS IAM privilege escalation methods
MITRE ATT&CK Matrices of AWS
AWS security workshops
ThreatModel for Amazon S3151almost 3 years ago: Library of all the attack scenarios on Amazon S3, and how to mitigate them following a risk-based approach

Reading Materials / Azure

Overiew of Azure Security
Azure security fundamentals
MicroBurst by NetSPI2,068almost 2 years ago: A collection of scripts for assessing Microsoft Azure security
MITRE ATT&CK Matrices of Azure
Azure security center workflow automation1,717almost 2 years ago

Reading Materials / GCP

Overiew of GCP Security
GKE security scenarios demo94about 2 years ago
MITRE ATT&CK Matrices of GCP
Security response automation209about 3 years ago

Reading Materials / Others

Cloud Security Research by RhinoSecurityLabs358over 6 years ago
CSA cloud security guidance v4
Appsecco provides training928almost 4 years ago
Cloud Risk Encyclopedia by Orca Security: 900+ documented cloud security risks, with ability to filter by cloud vendor, compliance framework, risk category, and criticality

Free Courses

AWS Security
DevSecOps – Kubernetes DevOps & Security
DevSecOps: Insecure Docker Registry
Learn Cloud Security, Kubernetes, DevSecOps, and more
Certified Kubernetes Security Specialist (CKS)

Bootcamps

On-Demand: DevSecOps: Beginner Edition Bootcamp
On-Demand: Cloud Security: AWS Edition Bootcamp
On-Demand: Container Security: Beginner Edition Bootcamp

Trainings

Attacking and Defending AWS

Certifications

CCSP – Certified Cloud Security Professional
AWS Certified Security - Specialty
Microsoft Certified: Azure Security Engineer Associate
Certified Kubernetes Security Specialist (CKS)

Resource / AWS

Bucket search by grayhatwarfare

Resource / Others

Mapping of On-Premises Security Controls vs. Major Cloud Providers Services

Backlinks from these awesome lists:

More related projects: