Awesome Lists

awesome-cloud-security

by 4ndersonLin

awesome listpushed almost 2 years ago

🛡️ Awesome Cloud Security Resources ⚔️

AI summary

Cloud Security Toolkit

A curated collection of cloud security resources and tools for assessing and securing cloud environments.

stars
2.1K
forks
319
watching
44
awesome list
1
entries
153
View on GitHub

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/4ndersonLin/awesome-cloud-security/links.svg)](https://awesome.facts.dev/awesome/4ndersonLin/awesome-cloud-security)
HTML
<a href="https://awesome.facts.dev/awesome/4ndersonLin/awesome-cloud-security"><img src="https://awesome.facts.dev/shield/4ndersonLin/awesome-cloud-security/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/4ndersonLin/awesome-cloud-security/links.svg

What's in the list

153 links in 20 sections, with live GitHub stats.activeno commit in 2y

Standards / Compliances

Standards / Benchmarks

Infrastructure

  • aws_pwn

    : A collection of AWS penetration testing junk

  • aws_ir

    : Python installable command line utility for mitigation of instance and key compromises

  • aws-firewall-factory

    : Deploy, update, and stage your WAFs while managing them centrally via FMS

  • aws-vault

    : A vault for securely storing and accessing AWS credentials in development environments

  • awspx

    : A graph-based tool for visualizing effective access and resource relationships within AWS

  • azucar

    : A security auditing tool for Azure environments

  • checkov

    : A static code analysis tool for infrastructure-as-code

  • cloud-forensics-utils

    : A python lib for DF & IR on the cloud

  • Cloud-Katana

    : Automate the execution of simulation steps in multi-cloud and hybrid cloud environments

  • cloudlist

    : Listing Assets from multiple Cloud Providers

  • Cloud Sniper

    : A platform designed to manage Cloud Security Operations

  • Cloudmapper

    : Analyze your AWS environments

  • Cloudmarker

    : A cloud monitoring tool and framework

  • Cloudsploit

    : Cloud security configuration checks

  • CloudQuery

    : Open source cloud asset inventory with set of pre-baked SQL for security and compliance

  • Cloud-custodian

    : Rules engine for cloud security, cost optimization, and governance

  • consoleme

    : A Central Control Plane for AWS Permissions and Access

  • cs suite

    : Tool for auditing the security posture of AWS/GCP/Azure

  • Deepfence ThreatMapper

    : Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless

  • dftimewolf

    : A multi-cloud framework for orchestrating forensic collection, processing and data export

  • diffy

    : Diffy is a digital forensics and incident response (DFIR) tool developed by Netflix

  • ElectricEye

    : Continuously monitor AWS services for configurations

  • Forseti security

    : GCP inventory monitoring and policy enforcement tool

  • Hammer

    : A multi-account cloud security tool for AWS. It identifies misconfigurations and insecure data exposures within most popular AWS resources

  • kics

    : Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code

  • Matano

    : Open source serverless security lake platform on AWS that lets you ingest, store, and analyze data into an Apache Iceberg data lake and run realtime Python detections as code

  • Metabadger

    : Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2)

  • Open policy agent

    : Policy-based control tool

  • pacbot

    : Policy as Code Bot

  • pacu

    : The AWS exploitation framework

  • PMapper

    : A tool for quickly evaluating IAM permissions in AWS

  • Prowler

    : Command line tool for AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool

  • ScoutSuite

    : Multi-cloud security auditing tool

  • Security Monkey

    : Monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time

  • SkyWrapper

    : Tool helps to discover suspicious creation forms and uses of temporary tokens in AWS

  • Smogcloud

    : Find cloud assets that no one wants exposed

  • Steampipe

    : A Postgres FDW that maps APIs to SQL, plus suites of and for AWS/Azure/GCP and many others

  • Terrascan

    : Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure

  • tfsec

    : Static analysis powered security scanner for Terraform code

  • Zeus

    : AWS Auditing & Hardening Tool

Container

  • auditkube

    : Audit for for EKS, AKS and GKE for HIPAA/PCI/SOC2 compliance and cloud security

  • Falco

    : Container runtime security

  • mkit

    : Managed kubernetes inspection tool

  • Open policy agent

    : Policy-based control tool

SaaS

  • aws-allowlister

    : Automatically compile an AWS Service Control Policy with your preferred compliance frameworks

  • binaryalert

    : Serverless S3 yara scanner

  • cloudsplaining

    : An AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report

  • Cloud Guardrails

    : Rapidly cherry-pick cloud security guardrails by generating Terraform files that create Azure Policy Initiatives

  • Function Shield

    : Protection/destection lib of aws lambda and gcp function

  • FestIN

    : S3 bucket finder and content discover

  • GCPBucketBrute

    : A script to enumerate Google Storage buckets

  • IAM Zero

    : Detects identity and access management issues and automatically suggests least-privilege policies

  • Lambda Guard

    : AWS Lambda auditing tool

  • Policy Sentry

    : IAM Least Privilege Policy Generator

  • S3 Inspector

    : Tool to check AWS S3 bucket permissions

  • Serverless Goat

    : A serverless application demonstrating common serverless security flaws

  • SkyArk

    : Tool to helps to discover, assess and secure the most privileged entities in Azure and AWS

Penetration testing/learning

  • AWSGoat

    : AWSGoat is a vulnerable by design AWS infrastructure featuring OWASP Top 10 web application security risks (2021) and AWS service based misconfigurations

  • ccat

    : Cloud Container Attack Tool

  • CloudBrute

    : A multiple cloud enumerator

  • cloudgoat

    : "Vulnerable by Design" AWS deployment tool

  • Leonidas

    : A framework for executing attacker actions in the cloud

  • Pwned Labs

    : Free hosted labs for learning cloud security

  • Sadcloud

    : Tool for spinning up insecure AWS infrastructure with Terraform

  • TerraGoat

    : Bridgecrew's "Vulnerable by Design" Terraform repository

  • WrongSecrets

    : A vulnerable app which demonstrates how to not use secrets. With AWS/Azure/GCP support

Native tools / AWS

Native tools / Azure

Native tools / GCP

Reading Materials / AWS

Reading Materials / Azure

Reading Materials / GCP

Reading Materials / Others

Free Courses

Bootcamps

Trainings

Certifications

Resource / AWS

Resource / Others

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.