Sadcloud is a tool for spinning up insecure AWS infrastructure with Terraform, supporting approximately 84 misconfigurations across 22 AWS Services. It was created to allow security researchers to misconfigure AWS for training purposes or assess AWS security tools, but it should not be run in production environments due to intentionally vulnerable configurations. Users are advised to set up a new AWS account to run this tool and to tear down all Terraform resources when not in use to minimize costs.
FEATURES
ALTERNATIVES
A project exploring minimal set of restrictions for running untrusted code using Linux containers in a concise codebase.
A CLI utility that makes it easier to switch between different AWS roles
A free training course and lab environment for learning to test and attack cloud infrastructure, including AWS and Azure.
A script and library for identifying risks in AWS IAM configuration
A small project for continuous auditing of internet-facing AWS services
DataCop is a custom AWS framework for mitigating S3 bucket attack vectors based on customer configuration.
Multi-cloud OSINT tool for enumerating public resources in AWS, Azure, and Google Cloud.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.