awesome-cloud-security

🛡️ Awesome Cloud Security Resources ⚔️

GitHub

2k stars
45 watching
314 forks
last commit: 4 months ago
Linked from 1 awesome list

awsaws-securityazureazure-securitycloud-computingcloud-securitycybersecuritygcpgcp-securitysecurity

Standards / Compliances

CSA STAR
ISO/IEC 27017:2015
ISO/IEC 27018:2019
MTCS SS 584

Standards / Benchmarks

CIS Benchmark

Tools / Infrastructure

aws_pwn 1,165 about 1 year ago : A collection of AWS penetration testing junk
aws_ir 340 about 3 years ago : Python installable command line utility for mitigation of instance and key compromises
aws-firewall-factory 233 5 days ago : Deploy, update, and stage your WAFs while managing them centrally via FMS
aws-vault 8,434 2 months ago : A vault for securely storing and accessing AWS credentials in development environments
awspx 911 about 2 years ago : A graph-based tool for visualizing effective access and resource relationships within AWS
azucar 557 almost 2 years ago : A security auditing tool for Azure environments
checkov 7,016 5 days ago : A static code analysis tool for infrastructure-as-code
cloud-forensics-utils 459 3 months ago : A python lib for DF & IR on the cloud
Cloud-Katana 243 7 months ago : Automate the execution of simulation steps in multi-cloud and hybrid cloud environments
cloudlist 844 5 days ago : Listing Assets from multiple Cloud Providers
Cloud Sniper 182 6 months ago : A platform designed to manage Cloud Security Operations
Cloudmapper 5,975 3 months ago : Analyze your AWS environments
Cloudmarker 219 about 2 months ago : A cloud monitoring tool and framework
Cloudsploit 3,307 11 days ago : Cloud security configuration checks
CloudQuery 5,807 5 days ago : Open source cloud asset inventory with set of pre-baked SQL for security and compliance
Cloud-custodian 5,384 8 days ago : Rules engine for cloud security, cost optimization, and governance
consoleme 3,115 3 months ago : A Central Control Plane for AWS Permissions and Access
cs suite 1,142 almost 2 years ago : Tool for auditing the security posture of AWS/GCP/Azure
Deepfence ThreatMapper 4,781 5 days ago : Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless
dftimewolf 290 17 days ago : A multi-cloud framework for orchestrating forensic collection, processing and data export
diffy 634 9 months ago : Diffy is a digital forensics and incident response (DFIR) tool developed by Netflix
ElectricEye 933 26 days ago : Continuously monitor AWS services for configurations
Forseti security 1,275 over 1 year ago : GCP inventory monitoring and policy enforcement tool
Hammer 435 about 1 year ago : A multi-account cloud security tool for AWS. It identifies misconfigurations and insecure data exposures within most popular AWS resources
kics 2,034 5 days ago : Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code
Matano 1,453 3 months ago : Open source serverless security lake platform on AWS that lets you ingest, store, and analyze data into an Apache Iceberg data lake and run realtime Python detections as code
Metabadger 138 7 months ago : Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2)
Open policy agent : Policy-based control tool
pacbot 1,287 almost 2 years ago : Policy as Code Bot
pacu 4,323 17 days ago : The AWS exploitation framework
Prowler 10,641 4 days ago : Command line tool for AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool
ScoutSuite 6,628 29 days ago : Multi-cloud security auditing tool
Security Monkey 4,351 over 3 years ago : Monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time
SkyWrapper 104 over 3 years ago : Tool helps to discover suspicious creation forms and uses of temporary tokens in AWS
Smogcloud 331 about 4 years ago : Find cloud assets that no one wants exposed
Steampipe 6,854 5 days ago : A Postgres FDW that maps APIs to SQL, plus suites of and for AWS/Azure/GCP and many others
Terrascan 4,700 15 days ago : Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure
tfsec 6,663 26 days ago : Static analysis powered security scanner for Terraform code
Zeus 707 over 4 years ago : AWS Auditing & Hardening Tool

Tools / Container

auditkube 109 5 days ago : Audit for for EKS, AKS and GKE for HIPAA/PCI/SOC2 compliance and cloud security
Falco 7,291 5 days ago : Container runtime security
mkit 400 about 3 years ago : Managed kubernetes inspection tool
Open policy agent : Policy-based control tool

Tools / SaaS

aws-allowlister 222 about 1 year ago : Automatically compile an AWS Service Control Policy with your preferred compliance frameworks
binaryalert 1,405 10 months ago : Serverless S3 yara scanner
cloudsplaining 1,973 12 days ago : An AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report
Cloud Guardrails 181 11 months ago : Rapidly cherry-pick cloud security guardrails by generating Terraform files that create Azure Policy Initiatives
Function Shield 39 almost 5 years ago : Protection/destection lib of aws lambda and gcp function
FestIN 228 almost 4 years ago : S3 bucket finder and content discover
GCPBucketBrute 479 over 1 year ago : A script to enumerate Google Storage buckets
IAM Zero 248 over 1 year ago : Detects identity and access management issues and automatically suggests least-privilege policies
Lambda Guard 400 about 2 years ago : AWS Lambda auditing tool
Policy Sentry 1,988 12 days ago : IAM Least Privilege Policy Generator
S3 Inspector : Tool to check AWS S3 bucket permissions
Serverless Goat 314 2 months ago : A serverless application demonstrating common serverless security flaws
SkyArk 867 almost 2 years ago : Tool to helps to discover, assess and secure the most privileged entities in Azure and AWS

Tools / Penetration testing/learning

ccat 585 almost 5 years ago : Cloud Container Attack Tool
CloudBrute 859 about 2 months ago : A multiple cloud enumerator
cloudgoat 2,910 9 days ago : "Vulnerable by Design" AWS deployment tool
Leonidas 474 about 1 month ago : A framework for executing attacker actions in the cloud
Pwned Labs : Free hosted labs for learning cloud security
Sadcloud 646 12 months ago : Tool for spinning up insecure AWS infrastructure with Terraform
TerraGoat 1,139 22 days ago : Bridgecrew's "Vulnerable by Design" Terraform repository
WrongSecrets 1,208 5 days ago : A vulnerable app which demonstrates how to not use secrets. With AWS/Azure/GCP support

Tools / Native tools / AWS

Artifact : Compliance report selfservice
Audit manager : Continuously audit for AWS usage
Certificate Manager : Private CA and certificate management service
CloudTrail : Record and log API call on AWS
Config : Configuration and resources relationship monitoring
Elastic Disaster Recovery : Application recovery service
Detective : Analyze and visualize security data and help security investigations
Firewall Manager : Firewall management service
GuardDuty : IDS service
CloudHSM : HSM service
Inspector : Vulnerability discover and assessment service
KMS : KMS service
Macie : Fully managed data security and data privacy service for S3
Network Firewall : Network firewall service
Secret Manager : Credential management service
Security Hub : Integration service for other AWS and third-party security service
Shield : DDoS protection service
Single Sign-On : Service of centrally manage access AWS or application
ThreatMapper 4,781 5 days ago : Identify vulnerabilities in running containers, images, hosts and repositories
VPC Flowlog : Log of network traffic
WAF : Web application firewall service

Tools / Native tools / Azure

Application Gateway : L7 load balancer with optional WAF function
DDoS Protection : DDoS protection service
Dedicated HSM : HSM service
Key Vault : KMS service
Monitor : API log and monitoring related service
Security Center : Integration service for other Azure and third-party security service
Sentinel : SIEM service

Tools / Native tools / GCP

Access Transparency : Transparency log and control of GCP
Apigee Sense : API security monitoring, detection, mitigation
Armor : DDoS protection and WAF service
Asset Inventory : Asset monitoring service
Assured workloads : Secure and compliant workloads
Audit Logs : API logs
Binanry Authorization : Binary authorization service for containers and serverless
Cloud HSM : HSM service
Cloud IDS : IDS service
Confidential VM : Encrypt data in use with VM
Context-aware Access : Enable zero trust access to applications and infrastructure
DLP : DLP service:
EKM : External key management service
Identity-Aware Proxy : Identity-Aware Proxy for protect the internal service
KMS : KMS service
Policy Intelligence : Detect the policy related risk
Security Command Center : Integration service for other GCP security service
Security Scanner : Application security scanner for GAE, GCE, GKE
Shielded VM : VM with secure boot and vTPM
Event Threat Detection : Threat dection service
VPC Service Controls : GCP service security perimeter control

Reading Materials / AWS

Overiew of AWS Security
AWS-IAM-Privilege-Escalation by RhinoSecurityLabs 892 about 5 years ago : A centralized source of all AWS IAM privilege escalation methods
MITRE ATT&CK Matrices of AWS
AWS security workshops
ThreatModel for Amazon S3 148 about 1 year ago : Library of all the attack scenarios on Amazon S3, and how to mitigate them following a risk-based approach

Reading Materials / Azure

Overiew of Azure Security
Azure security fundamentals
MicroBurst by NetSPI 2,019 12 days ago : A collection of scripts for assessing Microsoft Azure security
MITRE ATT&CK Matrices of Azure
Azure security center workflow automation 1,686 9 days ago

Reading Materials / GCP

Overiew of GCP Security
GKE security scenarios demo 94 about 2 months ago
MITRE ATT&CK Matrices of GCP
Security response automation 209 about 1 year ago

Reading Materials / Others

Cloud Security Research by RhinoSecurityLabs 352 over 4 years ago
CSA cloud security guidance v4
Appsecco provides training 923 almost 2 years ago
Cloud Risk Encyclopedia by Orca Security : 900+ documented cloud security risks, with ability to filter by cloud vendor, compliance framework, risk category, and criticality

Free Courses

AWS Security
DevSecOps – Kubernetes DevOps & Security
DevSecOps: Insecure Docker Registry
Learn Cloud Security, Kubernetes, DevSecOps, and more
Certified Kubernetes Security Specialist (CKS)

Bootcamps

On-Demand: DevSecOps: Beginner Edition Bootcamp
On-Demand: Cloud Security: AWS Edition Bootcamp
On-Demand: Container Security: Beginner Edition Bootcamp

Trainings

Attacking and Defending AWS

Certifications

CCSP – Certified Cloud Security Professional
AWS Certified Security - Specialty
Microsoft Certified: Azure Security Engineer Associate
Certified Kubernetes Security Specialist (CKS)

Resource / AWS

Bucket search by grayhatwarfare

Resource / Others

Mapping of On-Premises Security Controls vs. Major Cloud Providers Services

Backlinks from these awesome lists: