Sadcloud is a tool for spinning up insecure AWS infrastructure with Terraform, supporting approximately 84 misconfigurations across 22 AWS Services. It was created to allow security researchers to misconfigure AWS for training purposes or assess AWS security tools, but it should not be run in production environments due to intentionally vulnerable configurations. Users are advised to set up a new AWS account to run this tool and to tear down all Terraform resources when not in use to minimize costs.
FEATURES
ALTERNATIVES
Automatically compile AWS SCPs for compliant AWS services based on preferred frameworks.
An open-source security tool for AWS, Azure, Google Cloud, and Kubernetes security assessments and audits.
Krampus is a security solution for managing AWS objects and can be used as a cost-control tool.
FunctionShield is a Serverless Security Library for Developers to enforce strict security controls on AWS Lambda & Google Cloud Functions runtimes.
AWS Cloud Security offers security services and compliance tools for securing data and applications on AWS.
Docker's Actuary automates security best-practices checks for Docker containers.
Tool for assessing compliance and running vulnerability scans on Docker images.
Cloud Security Suite (cs-suite) - Version 3.0 Usage for cloud security audits on AWS, GCP, Azure, and DigitalOcean.
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

Kriptos
An AI-driven data classification and governance platform that automatically discovers, analyzes, and labels sensitive information while providing risk management and compliance capabilities.

System Two Security
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.

Aikido Security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.

Permiso
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.

Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.

Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.