
AWSome-Pentesting
My cheatsheet notes to pentest AWS infrastructure

My cheatsheet notes to pentest AWS infrastructure

Tooling for assessing an Azure AD tenant state and configuration

Discover resources created in an AWS account.

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

GCPGoat : A Damn Vulnerable GCP Infrastructure

Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services

This chef cookbook provides secure ssh-client and ssh-server configurations.

Hardened Debian GNU/Linux distro auditing

A security toolkit for Amazon S3

Curated catalog of AWS resource types that can be publicly exposed, with CLI commands for creating and auditing public access configurations across…

AWS Identity and Access Management Visualizer and Anomaly Finder

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…