Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
翻译 - 在配置云原生基础架构之前,将整个基础架构中的合规性和安全违规行为作为代码进行检测,以降低风险。
🛡️ Awesome Cloud Security Resources ⚔️
☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
翻译 - ☁️ :zap:云的粒度、可操作的对手仿真。
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production...
翻译 - TerraGoat是Bridgecrew的“设计易受攻击” Terraform存储库。 TerraGoat是一个学习和培训项目,它演示了常见的配置错误如何将其发现到生产云环境中。
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & ...
TerraformGoat is HXSecurity research lab's "Vulnerable by Design" multi cloud deployment tool.
TerraformGoat is HXSecurity research lab's "Vulnerable by Design" multi cloud deployment tool.
cloudgrep is grep for cloud storage
Monitor the internet attack surface of various public cloud environments. Currently supports AWS, GCP, Azure, DigitalOcean and Oracle Cloud.
Hayat is a script for report and analyze Google Cloud Platform resources.
A Project dedicated to documenting various attack and detection vectors that can be encountered within Google Cloud Platform (GCP).
Offensive Terraform Website
Offensive Terraform Website
Based on Lightspin proprietary data, research, and our tracking of cloud security trends in the market, our research team has compiled a list of the 2022 Top 7 Cloud Attack Paths across AWS, Azure, GC...
Welcome to the Cloud Security Toolkit repository, your all-in-one destination for cutting-edge cloud security resources! Whether you're diving into offensive strategies, mastering threat hunting, or b...
#区块链#A collection of awesome software, libraries, documents, books, resources and cool stuff about cryptography in Cybersecurity.
Terraform to run Scoutsuite security scan of projects within a Google Cloud Org. Report will be published to a GCS bucket.
Super-powered know how tools for AWS and GCP cloud security
Cloud SQL Proxy works with encrypted credential file.