Nimbostratus Tools for fingerprinting and exploiting Amazon cloud infrastructures. These tools are a PoC which I developed for my "Pivoting in Amazon clouds" talk, developed using the great boto library for accessing Amazon's API. For more information visit the project page Feel free to report bugs, fork and send pull-requests. You can also drop me a line at @w3af.
FEATURES
ALTERNATIVES
A framework to analyze container images and gather useful information.
Conmachi is a Golang tool for scanning container environments for security issues.
Multi-cloud OSINT tool for enumerating public resources in AWS, Azure, and Google Cloud.
AWS serverless cloud security tool for parsing and alerting on CloudTrail logs using EQL.
A Terraform module to set up a secure AWS account configuration baseline
A tool for spinning up insecure AWS infrastructure with Terraform for training and security assessment purposes.
CloudDefense.AI is a Cloud Native Application Protection Platform (CNAPP) that safeguards cloud infrastructure and cloud-native apps with expertise, precision, and confidence.
Managed Kubernetes Inspection Tool leveraging FOSS tools to query and validate security-related settings.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.