awesome-aws-security/README.md
2019-12-30 23:35:32 +05:30

7.1 KiB

Awesome AWS Security Awesome

A common curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are obviously related to AWS Security. List inspired by the awesome list thing.

Books

  1. Hands-On AWS Penetration Testing with Kali Linux by PackT
  2. Mastering AWS Security by PackT
  3. Security Best Practices on AWS by PackT
  4. Cloud Security Automation
  5. AWS Automation Cookbook

AWS Whitepapers

  1. AWS Security Best Practices
  2. AWS Security Pillar
  3. AWS Overview of Security Processes
  4. NIST Cybersecurity Framework
  5. AWS Risk And Compliance
  6. AWS Auditing Security Checklist
  7. AWS HIPAA Compliance Whitepaper

Videos

  1. AWS Security by Design - Youtube
  2. Account Security with IAM - Youtube
  3. AWS re:Inforce 2019 Security Best Practices - Youtube
  4. AWS Cloud Security Playlist - Youtube

Online Tutorials/Blogs/Presentations

  1. AWS Security official blog
  2. AWS in Plain English
  3. Why the CIA trusts AWS
  4. Fundamentals of AWS Security - Presentation from AWS
  5. Introduction to AWS Security - Presentation from AWS

Online Courses (Paid/Free)

  1. AWS Fundamentals: Address Security Risks - Coursera
  2. Cloud Computing Security - Coursera
  3. AWS: Getting started with Cloud Security - EdX
  4. AWS Certified Security Specialty - Udemy by Zeal Vora
  5. AWS Certified Security Specialty - From Acloud.guru
  6. AWS Advanced Security - Udemy
  7. AWS for Architects: Advanced Security - Linkedin Learn by Lynn Langit
  8. Practical Event Driven Security with AWS - Acloud.guru
  9. Learning Path for AWS Security - Nicely designed the learning path who wants to be an AWS Security Experts from Acloud.guru
  10. Cloud Hacking course - From NotSoSercure

Tools of Trade

  1. AWS Security Products
  2. Arsenal of AWS Security Tools - Collection of all security category tools and products
  3. AWS Security Automation - Collection of scripts and resources for DevSecOps and Automated Incident Response Security
  4. Security Monkey - Monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.
  5. truffleHog - Searches through git repositories for high entropy strings and secrets, digging deep into commit history
  6. gitleaks - Audit git repos for secrets
  7. AWS Security Benchmark - Open source demos, concept and guidance related to the AWS CIS Foundation framework.
  8. S3 Inspector - Tool to check AWS S3 bucket permissions
  9. ScoutSuite - Multi-Cloud Security Auditing Tool
  10. Prowler - AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool.
  11. AWS Vault - A vault for securely storing and accessing AWS credentials in development environments
  12. AWS PWN - A collection of AWS penetration testing junk
  13. Pacu - AWS Penetration Testing Toolkits
  14. Zeus - AWS Auditing and Hardening tool
  15. Cloud Mapper - Analyze your AWS environments (Python)

Security Practice and CTFs

  1. AWS Well Architected Security Labs
  2. Flaws to learn common mistakes in AWS through challenge
  3. Flaws2 focuses on AWS security concepts through various challenge levels
  4. CloudGoat - Vulnerable by Design AWS infrastructure setup tool
  5. OWASP ServerlessGoat - OWASP ServerlessGoat is a deliberately insecure realistic AWS Lambda serverless application maintained by OWASP for educational purposes.

AWS Security Breaches

  1. AWS Security breaches - 2017
  2. 200 million voters data leak - A lesson in AWS Security
  3. Imperva blames data breach on Stolen AWS API keys
  4. Tesla's Amazon cloud account was hacked and used to mine cryptocurrency
  5. 10 worst Amazon S3 breaches
  6. Lion Air the Latest to Get Tripped Up by Misconfigured AWS S3

Contributors

Please refer the guidelines at contribute.md for details.

Thanks to the following folks who made contributions to this project.

Get your name listed here

List of Contributors