lightspin-2022-top-7-attack-paths

Cloud Attack Paths

Compiles research on cloud security trends and attack paths

Based on Lightspin proprietary data, research, and our tracking of cloud security trends in the market, our research team has compiled a list of the 2022 Top 7 Cloud Attack Paths across AWS, Azure, GCP, and Kubernetes as seen on the Lightspin Cloud Native Application Protection Platform.

GitHub

39 stars
2 watching
1 forks
last commit: about 4 years ago
Linked from 1 awesome list

attack-pathsattack-surfaceaws-securityawssecurityazure-securityazuresecuritycloud-securitycloudsecuritygcp-securitymitre-attackttps

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
hashishrajan/cloud-security-vulnerabilitiesLists publicly disclosed vulnerabilities in various cloud services.357
sergiomarotco/azure-devops-server-supply-chain-attack-treeAn attack tree model for identifying potential security vulnerabilities in an Azure DevOps Server supply chain.7
prevade/cloudjackChecks AWS accounts for subdomain hijacking vulnerabilities84
esonhugh/attack_codeAn introductory article on cloud security and development, covering various aspects of cloud computing, including infrastructure, storage, deployment, and security.536
datadog/stratus-red-teamProvides a tool to emulate offensive attack techniques in the cloud1,863
jlopp/physical-bitcoin-attacksCompiles known physical attacks on Bitcoin and cryptocurrency owners583
salesforce/cloudsplainingA tool that scans AWS IAM policies to identify security vulnerabilities and generates a report with recommendations for remediation2,009
cloud-architekt/azuread-attack-defenseA collection of attack scenarios and mitigation strategies for Microsoft Entra ID2,183
sukkaw/cloudflare-block-bad-bot-rulesetProtects websites from malicious crawlers and bots by filtering out suspicious traffic based on user-agent information211
bishopfox/smogcloudAutomatically identifies and monitors cloud assets exposed to the internet without authorization332
sbasu7241/aws-threat-simulation-and-detectionThis repository documents the simulation and detection of various AWS attack scenarios using Stratus Red Team and SumoLogic for logging and analysis.284
aquasecurity/cloudsploitA tool designed to detect security risks in cloud infrastructure accounts3,372
someengineering/fixinventoryTools to identify and remove critical risks in cloud infrastructure accounts by analyzing metadata from APIs of various cloud services1,617
azure/stormspotterA tool for analyzing and visualizing Azure objects to help security teams understand potential attack surfaces.1,555
dark-kinga/cloudtoolsA cloud asset management tool for detecting and managing cloud security vulnerabilities in various cloud services915