Sadcloud is a tool for spinning up insecure AWS infrastructure with Terraform, supporting approximately 84 misconfigurations across 22 AWS Services. It was created to allow security researchers to misconfigure AWS for training purposes or assess AWS security tools, but it should not be run in production environments due to intentionally vulnerable configurations. Users are advised to set up a new AWS account to run this tool and to tear down all Terraform resources when not in use to minimize costs.
FEATURES
ALTERNATIVES
A security tool that monitors AWS objects for ownership attribution, detects domain hijacking, and verifies security services.
A script and library for identifying risks in AWS IAM configuration
A cloud native security platform that uses behavioral fingerprinting and runtime verification to detect threats across Kubernetes environments, cloud infrastructure, and software supply chains.
A graph-based tool for visualizing effective access and resource relationships within AWS
Multi-cloud OSINT tool for enumerating public resources in AWS, Azure, and Google Cloud.
Monitors AWS and GCP accounts for policy changes and alerts on insecure configurations, with support for OpenStack and GitHub monitoring.
AWS Scout2 is a security tool for AWS administrators to assess their environment's security posture.
A project exploring minimal set of restrictions for running untrusted code using Linux containers in a concise codebase.
PINNED
InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
System Two Security
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.
Aikido Security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.
Permiso
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.