awesome-cloud-security
cloud security guide
A curated collection of resources and examples for improving cloud security
A curated list of awesome cloud security blogs, podcasts, standards, projects, and examples.
585 stars
18 watching
112 forks
last commit: about 2 years ago
Linked from 2 awesome lists
awesomeawesome-listawsaws-securitycloudcloud-securitydata-loss-preventiondlpelasticsearchgoogle-cloud-securityhacktoberfesthacktoberfest2023hacktoberfestcebuinformation-securityloggingnistoracle-cloud-securitysecuritysecurity-standardswaf
Awesome Cloud Security / Public Cloud Governance / URL Services | |||
| https://doc-{user_provided}-{random_id}.{region}.cloudsearch.amazonaws.com | |||
| ftp://s-{random_id}.server.transfer.{region}.amazonaws.com | s | ||
| https://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:8162 | |||
Awesome Cloud Security / Public Cloud Governance / MultiCloud Governance | |||
| Cloud Custodian | 5,488 | 11 months ago | |
| CloudQuary | 5,913 | 11 months ago | |
| Cloudsploit | 3,372 | 11 months ago | |
| ManageIQ by RedHat | 1,350 | 11 months ago | |
| Mist.io | 1,868 | over 1 year ago | |
| NeuVector | 1,122 | 11 months ago | |
| Triton by Joyent | 1,322 | about 1 year ago | |
Awesome Cloud Security / Kubernetes Operators / Aqua | |||
| Aqua Security Operator | |||
| Starboard Operator | |||
Awesome Cloud Security / Kubernetes Operators / Misc | |||
| Anchore - Anchore Engine Operator | |||
| Falco Security - Falco Operator | |||
| Quay - Project Quay Container Security | |||
| Snyk - Snyk Operator | |||
| Splunk - Splunk Operator for Kubernetes | |||
| Sysdig - Sysdig Agent Operator | |||
Awesome Cloud Security / Container Tools / Anchore | |||
| Anchore Engine | 1,589 | almost 3 years ago | |
| Grype | 8,970 | 11 months ago | |
| Kai | 63 | 11 months ago | |
| Syft | 6,371 | 11 months ago | |
Awesome Cloud Security / Container Tools / Aqua | |||
| Cloudsploit | 3,372 | 11 months ago | |
| Kube-Bench | 7,129 | 11 months ago | |
| Kube-Hunter | 4,774 | over 1 year ago | |
| Kubectl-who-can | 850 | over 1 year ago | |
| Trivy | 24,010 | 11 months ago | |
Awesome Cloud Security / Container Tools / Misc | |||
| Docker - Docker Bench for Security | 9,195 | about 1 year ago | |
| Elias - Dagda | 1,164 | over 2 years ago | |
| Falco Security - Falco | 7,460 | 11 months ago | |
| Harbor - Harbor | 24,406 | 11 months ago | |
| Quay - Clair | 10,409 | 11 months ago | |
| Snyk - Snyk | 4,979 | 11 months ago | |
| vchinnipilli - Kubestriker | 992 | over 1 year ago | |
Awesome Cloud Security / Cloud Security Standards | |||
| ISO/IEC 27017:2015 | |||
| ISO/IEC 27018:2019 | |||
| MTCS SS 584 | |||
| CCM | |||
| NIST 800-53 | |||
Awesome Cloud Security / Learning / Blogs | |||
| AWS Security | |||
| Azure Security | |||
| Dark Reading | |||
Awesome Cloud Security / Learning / Courses / Oracle | |||
| Oracle Cloud Security Administrator | |||
Awesome Cloud Security / Learning / Courses / A Cloud Guru / Learning Paths | |||
| AWS Security Path | |||
| Azure Security Path | |||
| GCP Security Path | |||
Awesome Cloud Security / Learning / Labs | |||
| AWS Workshops | |||
Awesome Cloud Security / Learning / Labs / AWS Workshops | |||
| AWS Identity: Using Amazon Cognito for serverless consumer apps | |||
| AWS Network Firewall Workshop | |||
| AWS Networking Workshop | |||
| Access Delegation | |||
| Amazon VPC Endpoint Workshop | |||
| Build a Vulnerability Management Program Using AWS for AWS | |||
| Data Discovery and Classification with Amazon Macie | |||
| Data Protection | |||
| DevSecOps - Integrating security into your pipeline | |||
| Disaster Recovery on AWS | |||
| Finding and addressing Network Misconfigurations on AWS | |||
| Firewall Manager Service - WAF Policy | |||
| Getting Hands on with Amazon GuardDuty | |||
| Hands on Network Firewall Workshop | |||
| Implementing DDoS Resiliency | |||
| Infrastructure Identity on AWS | |||
| Integrating security into your container pipeline | |||
| Integration, Prioritization, and Response with AWS Security Hub | |||
| Introduction to WAF | |||
| Permission boundaries: how to delegate permissions on AWS | |||
| Protecting workloads on AWS from the instance to the edge | |||
| Scaling threat detection and response on AWS | |||
| Serverless Identity | |||
Awesome Cloud Security / Learning / Labs | |||
| PagerDuty Training Lab | |||
Awesome Cloud Security / Learning / Labs / PagerDuty Training Lab | |||
| PagerDuty Training GitHub | 411 | over 2 years ago | |
| PagerDuty Training for Engineers | |||
| PagerDuty Training for Everyone: Part 1 | |||
| PagerDuty Training for Everyone: Part 2 | |||
Awesome Cloud Security / Learning / Podcasts | |||
| Azure DevOps Podcast | |||
| Cloud Security Podcast by Google | |||
| Security Now | |||
Awesome Cloud Security / Learning / Vulnerable By Design | |||
| CloudGoat by Rhino Security Labs | 2,991 | 11 months ago | |
| ServerlessGoat by OWASP | 320 | over 1 year ago | |
| WrongSecrets by OWASP | 1,246 | 11 months ago | |
Awesome Cloud Security / Certifications / Cloud Vendors | |||
| AWS Certified Security Specialty | |||
| Azure Security Engineer Associate | |||
| Google Professional Cloud Security Engineer | |||
| Oracle Cloud Platform Identity and Security Management | |||
Awesome Cloud Security / Certifications / ISC | |||
| CCSP - Certified Cloud Security Professional | |||
Awesome Cloud Security / Certifications / CSA | |||
| CCSK - Certificate of Cloud Security Knowledge | |||
| CCAK - Certificate of Cloud Auditing Knowledge | |||
Awesome Cloud Security / Projects / Alerting | |||
| 411 by Etsy | 973 | over 2 years ago | |
| ElastAlert by Yelp | 8,004 | about 1 year ago | |
| StreamAlert by Airbnb | 2,864 | about 2 years ago | |
Awesome Cloud Security / Projects / Automated Security Assessment | |||
| Prowler | 10,941 | 11 months ago | |
| CloudFox | 1,983 | about 1 year ago | |
| SkyArk | 877 | almost 3 years ago | |
| Pacu | 4,422 | 12 months ago | |
| Bucket Finder | |||
| Boto3 | |||
| Principal Mapper | 1,436 | about 1 year ago | |
| ScoutSuite | 6,794 | 12 months ago | |
| s3_objects_check | 75 | over 3 years ago | |
| cloudsplaining | 2,009 | 11 months ago | |
| weirdAAL | 787 | over 2 years ago | |
| cloudmapper | 6,017 | over 1 year ago | |
| NetSPI/AWS_Consoler | 225 | over 5 years ago | |
Awesome Cloud Security / Projects / Benchmarking | |||
| AWS Security Benchmark | 618 | almost 6 years ago | |
Awesome Cloud Security / Projects / Data Loss Prevention | |||
| Git Secrets by AWS Labs | 12,504 | over 1 year ago | |
Awesome Cloud Security / Projects / Firewall Management / globaldatanet | |||
| AWS Firewall Factory | 237 | 11 months ago | |
Awesome Cloud Security / Projects / Identity and Access Management / AWS Labs | |||
| AWS IAM Generator | 241 | over 4 years ago | |
Awesome Cloud Security / Projects / Identity and Access Management / Duo Labs | |||
| Parliament | 1,051 | over 1 year ago | |
| CloudTracker | 888 | almost 4 years ago | |
Awesome Cloud Security / Projects / Identity and Access Management / Netflix | |||
| Aardvark | 474 | about 1 year ago | |
| ConsoleMe | 3,153 | over 1 year ago | |
| PolicyUniverse | 427 | over 1 year ago | |
| Repokid | 1,124 | over 2 years ago | |
Awesome Cloud Security / Projects / Identity and Access Management / Pinterest | |||
| Knox | 1,235 | 11 months ago | |
Awesome Cloud Security / Projects / Identity and Access Management / Salesforce | |||
| Policy Sentry | 2,028 | 11 months ago | |
| CloudSplaining | 2,009 | 11 months ago | |
| AWS-AllowLister | 224 | about 2 years ago | |
| Terraform for Policy Guru | 29 | about 2 years ago | |
Awesome Cloud Security / Projects / Identity and Access Management / welldone.cloud | |||
| aws-lint-iam-policies | 119 | 11 months ago | |
Awesome Cloud Security / Projects / Identity and Access Management / Misc | |||
| AWS Missing Tools by CloudAvail | 1,340 | over 6 years ago | |
| Awesome IAM List | 1,781 | 12 months ago | |
| Enumerate IAM by Andres Riancho | 1,105 | over 1 year ago | |
| Kubernetes AWS IAM Authenticator by Kubernetes SIG | 2,218 | 11 months ago | |
Awesome Cloud Security / Projects / Incident Response / AWS | |||
| AWS Incident Response Playbooks by AWS Samples | 935 | over 1 year ago | |
| AWS Security Hub Automated Response and Remediation | 403 | 11 months ago | |
Awesome Cloud Security / Projects / Incident Response / Netflix | |||
| Dispatch by Netflix | 5,188 | 11 months ago | |
Awesome Cloud Security / Projects / Incident Response / PagerDuty | |||
| PagerDuty Automated Remediation Docs | 7 | over 2 years ago | |
| PagerDuty Business Response Docs | 8 | almost 4 years ago | |
| PagerDuty DevSecOps Docs | 13 | almost 4 years ago | |
| PagerDuty Full Case Ownership Docs | 5 | almost 4 years ago | |
| PagerDuty Full Service Ownership Docs | 22 | 11 months ago | |
| PagerDuty Going OnCall Docs | 7 | about 3 years ago | |
| PagerDuty Incident Response Docs | 1,023 | about 2 years ago | |
| PagerDuty Operational Review Docs | 20 | almost 4 years ago | |
| PagerDuty PostMortem Docs | 65 | over 3 years ago | |
| PagerDuty Retrospectives Docs | 9 | about 3 years ago | |
| PagerDuty Stakeholder Communication Docs | 9 | almost 3 years ago | |
Awesome Cloud Security / Projects / Incident Response / Velocidex | |||
| Velociraptor | 3,020 | 11 months ago | |
Awesome Cloud Security / Projects / Spring | |||
| Spring Cloud Security | 27 | 11 months ago | |
Awesome Cloud Security / Projects / Threat modeling | |||
| ThreatModel for Amazon S3 | 151 | about 2 years ago | Library of all the attack scenarios on Amazon S3 and how to mitigate them, following a risk-based approach |
Awesome Cloud Security / Examples / Ex. Automated Security Assessment | |||
| AWS Config Rules Repository | 1,621 | about 1 year ago | |
| AWS Inspector Agent Autodeploy | 28 | over 7 years ago | |
| AWS Inspector Auto Remediation | 58 | over 7 years ago | |
| AWS Inspector Lambda Finding Processor | 39 | over 7 years ago | |
Awesome Cloud Security / Examples / Ex. Identity and Access Management | |||
| Amazon Cognito Streams connector for Amazon Redshift | 9 | over 5 years ago | |
Awesome Cloud Security / Examples / Ex. Logging | |||
| AWS Centralized Logging | 253 | over 1 year ago | |
| AWS Config Snapshots to ElasticSearch | 71 | over 5 years ago | |
| AWS CloudWatch Events Monitor Security Groups | 25 | almost 6 years ago | |
Awesome Cloud Security / Examples / Ex. Web Application Firewall | |||
| AWS WAF Sample | 512 | almost 6 years ago | |
| AWS WAF Security Automations | 863 | about 1 year ago | |
Awesome Cloud Security / Misc / Other Awesome Lists | |||
| Awesome Cloud Cost Control | 41 | about 2 years ago | |
| Awesome Cloud Native Security | 309 | almost 2 years ago | |
| Awesome Cloud Security | 585 | about 2 years ago | |
| Awesome IAM List | 1,781 | 12 months ago | |
| Awesome Incident Response List | 7,728 | over 1 year ago | |
| Awesome Shodan Queries | 5,955 | over 1 year ago | |