Free Security and Hacking eBooks
-
Updated
Jul 10, 2019
{{ message }}
Free Security and Hacking eBooks
A Central Control Plane for AWS Permissions and Access
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground
There's a lot of work that would need to be done to upgrade the report to use Vue 3, which is almost 2 years old at this point (Cloudsplaining uses Vue 2). I know there is some work required to upgrade the report to use Vue 3, but I don't have capacity for it right now.
I'd also like to get some upgrades to the Javascript dependencies since they are outdated but can't seem to upgrade them witho
Dependabot has identified several security vulnerabilities in the 3rd party libraries Pacbot relies on. In most cases, these vulnerabilities can be resolved by upgrading the library to the most current version.
Maintainers, if you're internal to T-Mobile, you should have been seeing these security alerts coming in over the last several weeks. *Please respond to these in a timely ma
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
Idea: automatically generate images showing the ATT&CK Tactics (not techniques) coverage
Columns: ATT&CK Tactics
Rows: Stratus Red Team attack techniques
Open source device management, built on osquery.
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS
An encyclopedia for offensive and defensive security knowledge in cloud native technologies.
Continuously monitor your AWS attack surface and evaluate services for configurations that can lead to degradation of confidentiality, integrity or availability. All results can be exported to Security Hub, JSON, CSV, Databases, and more for further aggregation and analysis.
runner集成了weakpass等插件,但是不支持weakpass的自定义字典等非通用化参数设置
A Huge Learning Resources with Labs For Offensive Security Players
Awesome cloud enumerator
Knowledge seeks no man
awesome cloud security || 收集一些国内外不错的云安全资源,该项目主要面向国内的安全人员
Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security
Find cloud assets that no one wants exposed
Cloud security monitoring tool and framework
From the Common Fate Community Slack:
We’re getting this error when trying to use aws ssm start-session - I couldn’t see anything online but now I’m reading Brian’s comment above is this something to do with the way granted is storing credentials? Is the SSM session manager plugin not compatible or something?
----------ERROR------- Encountered error while initiating handshake. KM
awesome resources about cloud native security
Identity & Access Management simplified and secure.
Automatically compile an AWS Service Control Policy that ONLY allows AWS services that are compliant with your preferred compliance frameworks.
Cloud Security Operations Orchestrator
Curated list of awesome cloud security blogs, podcasts, standards, projects, and examples.
Add a description, image, and links to the cloud-security topic page so that developers can more easily learn about it.
To associate your repository with the cloud-security topic, visit your repo's landing page and select "manage topics."
Enhancement Request
Other security scanning tools (e.g.
checkovandtfsec) have a--soft-failflag or equivalent option that allows you to always exit with 0 status.Extremely useful when running the tool without halting a pipeline for example.
I currently use a workaround, but something more concrete would be very desira