SkyWrapper is an open-source project that analyzes behaviors of temporary tokens in an AWS account to detect suspicious creation forms and uses, creating an excel sheet of all living temporary tokens and providing a summary of findings after each run. To use SkyWrapper, fill in the required data in the config file, ensure users have necessary permissions, and run the python script. Required permissions include actions like s3:GetObject and iam:ListAttachedRolePolicies.
FEATURES
ALTERNATIVES
Nuvola is a tool for security analysis on AWS environments with a focus on creating a digital twin of cloud platforms.
A security tool that monitors AWS objects for ownership attribution, detects domain hijacking, and verifies security services.
A dynamic infrastructure framework for efficient multi-cloud security operations and distributed scanning.
A framework for executing attacker actions in the cloud with YAML-based format for defining TTPs and detection properties, deployable via AWS-native CI/CD pipeline.
LogRhythm SIEM is a comprehensive security information and event management platform that collects, analyzes, and responds to security events across an organization's IT infrastructure.
gVisor is an application kernel that provides isolation for running sandboxed containers.
Implements a cloud version of the Shadow Copy attack against domain controllers in AWS, allowing theft of domain user hashes.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.