An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with aws-security

A curated list of projects in awesome lists tagged with aws-security .

https://github.com/bridgecrewio/checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

aws aws-security azure cloudformation compliance devops gcp hacktoberfest infrastructure-as-code kubernetes scans static-analysis terraform

Last synced: 05 Jun 2026

https://github.com/tenable/terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

architecture aws aws-security azure-security cloud-security cloudsecurity devops devsecops gcp-security iac infrastructure infrastructure-as-code kubernetes sast scans security security-tools security-violations terraform terrascan

Last synced: 12 May 2025

https://github.com/jassics/security-study-plan

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...

api-security application-security appsec appsec-tutorials aws-security azure-security cybersecurity cybersecurity-education devsecops-university gcp-security infosec pentesting security-testing study-guide study-plan study-planner

Last synced: 09 Feb 2026

https://github.com/rhinosecuritylabs/pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

aws aws-security penetration-testing python security

Last synced: 10 Apr 2025

https://github.com/RhinoSecurityLabs/pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

aws aws-security penetration-testing python security

Last synced: 23 Mar 2025

https://github.com/Netflix/security_monkey

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

aws aws-ec2 aws-iam aws-policy-tracking aws-s3 aws-security aws-sqs aws-vpc boto boto3 botocore python security

Last synced: 15 Mar 2025

https://github.com/netflix/security_monkey

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

aws aws-ec2 aws-iam aws-policy-tracking aws-s3 aws-security aws-sqs aws-vpc boto boto3 botocore python security

Last synced: 29 Sep 2025

https://github.com/salesforce/cloudsplaining

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

aws aws-iam aws-security cloud cloud-security hacktoberfest iam salesforce security

Last synced: 16 May 2025

https://github.com/matanolabs/matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

alerting apache-iceberg aws aws-security big-data cloud cloud-native cloud-security cybersecurity detection-engineering dfir log-analytics log-management rust secops security security-tools serverless siem threat-hunting

Last synced: 14 May 2025

https://github.com/bridgecrewio/terragoat

TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

aws-security azure-security cloud-security devsecops gcp-security goat terraform

Last synced: 23 Apr 2025

https://github.com/securityftw/cs-suite

Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

aws-audit aws-security azure azure-audit azure-security cloud-security gcp gcp-audit-report security security-audit security-tools

Last synced: 16 May 2025

https://github.com/SecurityFTW/cs-suite

Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

aws-audit aws-security azure azure-audit azure-security cloud-security gcp gcp-audit-report security security-audit security-tools

Last synced: 08 Apr 2025

https://github.com/FSecureLABS/awspx

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

aws aws-security graph-theory pentesting

Last synced: 17 Aug 2025

https://github.com/reverseclabs/awspx

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

aws aws-security graph-theory pentesting

Last synced: 01 Jul 2025

https://github.com/ReversecLabs/awspx

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

aws aws-security graph-theory pentesting

Last synced: 12 May 2025

https://github.com/WithSecureLabs/awspx

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

aws aws-security graph-theory pentesting

Last synced: 29 Apr 2025

https://github.com/appsecco/breaking-and-pwning-apps-and-servers-aws-azure-training

Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!

application-security aws-security azure-security free opensource penetration-testing pentesting

Last synced: 23 Mar 2025

https://github.com/jonrau1/ElectricEye

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

asset-management attack-surface-management aws aws-audit aws-compliance aws-security cloud-auditing cloud-compliance-reporting cloud-security compliance devsecops gcp-security google-cloud-security multicloud saas-security security-audit security-engineering security-hub security-monitoring security-tools

Last synced: 01 Apr 2025

https://github.com/hxsecurity/terraformgoat

TerraformGoat is HXSecurity research lab's "Vulnerable by Design" multi cloud deployment tool.

aws-security azure-security cloud-security cloudsecurity gcp gcp-security kubernetes-security security terraform

Last synced: 05 Apr 2025

https://github.com/HXSecurity/TerraformGoat

TerraformGoat is HXSecurity research lab's "Vulnerable by Design" multi cloud deployment tool.

aws-security azure-security cloud-security cloudsecurity gcp gcp-security kubernetes-security security terraform

Last synced: 11 May 2025

https://github.com/dowjones/hammer

Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)

aws aws-security cloudsecurity devsecops

Last synced: 05 Apr 2025

https://github.com/skyscanner/cfripper

Library and CLI tool for analysing CloudFormation templates and check them for security compliance.

aws aws-security cfripper cloud-governance cloudformation cloudformation-linter cloudformation-template compliance static-analysis

Last synced: 13 Apr 2025

https://github.com/Skyscanner/cfripper

Library and CLI tool for analysing CloudFormation templates and check them for security compliance.

aws aws-security cfripper cloud-governance cloudformation cloudformation-linter cloudformation-template compliance static-analysis

Last synced: 01 Apr 2025

https://github.com/awslabs/iam-policy-autopilot

IAM Policy Autopilot is an open source static code analysis tool that helps you quickly create baseline AWS IAM policies that you can refine as your application evolves. This tool is available as a command-line utility and MCP server for use within AI coding assistants for quickly building IAM policies.

aws aws-iam aws-iam-policies aws-security cli cloud-security code-analysis iam iam-policy mcp mcp-server policy-generation policy-generator static-code-analysis

Last synced: 29 May 2026

https://github.com/jassics/cybersecurity-roadmap

Skills and career roadmap for various security roles like application security, cloud security, DevSecOps, security engineer, security researchers, pentesting, api security, network security, mobile security and so on with helpful resources, guidelines

application-security aws-security career-development career-guide career-plan career-roadmaps cloud-security cybersecurity-awareness cybersecurity-career-path devsecops interview-questions network-security security security-automation security-questions security-tools

Last synced: 26 Jan 2026

https://github.com/datadog/managed-kubernetes-auditing-toolkit

All-in-one auditing toolkit for identifying common security issues in managed Kubernetes environments. Currently supports Amazon EKS.

aws-eks aws-security eks kubernetes kubernetes-security managed-kubernetes

Last synced: 06 Apr 2025

https://github.com/DataDog/managed-kubernetes-auditing-toolkit

All-in-one auditing toolkit for identifying common security issues in managed Kubernetes environments. Currently supports Amazon EKS.

aws-eks aws-security eks kubernetes kubernetes-security managed-kubernetes

Last synced: 13 Apr 2025

https://github.com/cr0hn/festin

FestIn - Open S3 Bucket Scanner

aws-security s3 s3-bucket s3-security

Last synced: 06 Apr 2025

https://github.com/mlevit/aws-auto-remediate

Open source application to instantly remediate common security issues through the use of AWS Config

aws aws-compliance aws-security cloud lambda remediation security security-tools serverless serverless-framework

Last synced: 16 Apr 2025

https://github.com/goldfiglabs/rpCheckup

rpCheckup is an AWS resource policy security checkup tool that identifies public, external account access, intra-org account access, and private resources.

aws aws-security cloudsecurity cspm ec2 infosec resourcepolicy s3

Last synced: 10 May 2025

https://github.com/antgroup/cloudrec

CloudRec is an open source multi-cloud security posture management (CSPM) platform designed to help organizations improve the security of their cloud environments.

alibabacloud aws-security cloud cloud-security cspm cybersecurity devsecops gcp-security multi-cloud opa scans security

Last synced: 02 Aug 2025

https://github.com/riskprofiler/CloudFrontier

Monitor the internet attack surface of various public cloud environments. Currently supports AWS, GCP, Azure, DigitalOcean and Oracle Cloud.

api-gateway aws aws-security azure azure-security cloud-security cloudsecurity cyber-security cybersecurity digitalocean dynamodb gcp gcp-security lambda-functions oracle serverless serverless-framework shadow-risk shadowrisk

Last synced: 16 May 2025

https://github.com/bridgecrewio/cfngoat

Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

aws-security cloudformation cloudsecurity devsecops

Last synced: 01 Apr 2025

https://github.com/mitre/aws-foundations-cis-baseline

InSpec profile to validate your VPC to the standards of the CIS Amazon Web Services Foundations Benchmark

aws aws-security cis cloud ia inspec inspec-profile mitre-corporation mitre-inspec mitre-saf security

Last synced: 05 Apr 2025

https://github.com/jonrau1/SyntheticSun

SyntheticSun is a defense-in-depth security automation and monitoring framework which utilizes threat intelligence, machine learning, managed AWS security services and, serverless technologies to continuously prevent, detect and respond to threats.

anomaly-detection automation aws aws-security aws-serverless data-science data-visualization elasticsearch geolocation guardduty incident-response kibana machine-learning misp sagemaker security-automation security-tools serverless threat-detection threat-intelligence

Last synced: 12 Jul 2025

https://github.com/sendgrid/krampus

The original AWS security enforcer™

aws aws-lambda aws-security aws-security-automation infosec

Last synced: 05 Sep 2025

https://github.com/bridgecrewio/cdkgoat

CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

aws-cdk aws-security cloud-security cloudformation devsecops

Last synced: 22 Apr 2025

https://github.com/lightspin-tech/lightspin-2022-top-7-attack-paths

Based on Lightspin proprietary data, research, and our tracking of cloud security trends in the market, our research team has compiled a list of the 2022 Top 7 Cloud Attack Paths across AWS, Azure, GCP, and Kubernetes as seen on the Lightspin Cloud Native Application Protection Platform.

attack-paths attack-surface aws-security awssecurity azure-security azuresecurity cloud-security cloudsecurity gcp-security mitre-attack ttps

Last synced: 11 May 2025

https://github.com/3CORESec/AWS-AutoMirror

Automation of VPC Traffic Mirror Sessions in AWS

aws aws-lambda aws-security aws-security-automation network-security-monitoring

Last synced: 16 May 2025

https://github.com/aws-solutions/automations-for-aws-firewall-manager

The Automations For AWS Firewall Manager solution is intended for customers looking to easily manage consistent security posture across their entire AWS Organization. The solution uses AWS Firewall Manager Service.

aws aws-firewall-manager aws-security firewall

Last synced: 21 Aug 2025

https://github.com/jgamblin/defensive-s3-buckets

Defensive S3 Bucket Squating

aws-s3 aws-security cloud-security

Last synced: 29 Apr 2025

https://github.com/salesforce/terraform-provider-policyguru

Terraform provider for Policy Sentry (IAM least privilege generator and auditor)

aws aws-security cloud cloudsecurity hacktoberfest iam salesforce security

Last synced: 15 Apr 2025

https://github.com/mitre/cis-aws-foundations-hardening

(WIP) A terraform / kitchen-terraform hardening baseline for the cis-aws-foundations-baseline

aws aws-hardening aws-security cis cis-aws-benchmark inspec kitchen-terraform mitre-corporation mitre-inspec test-kitchen wip

Last synced: 06 Jul 2025

https://github.com/eshlomo1/cloudsec

Welcome to the Cloud Security Toolkit repository, your all-in-one destination for cutting-edge cloud security resources! Whether you're diving into offensive strategies, mastering threat hunting, or bolstering your blue-team defenses, this repo has you covered.

aws-security azure azure-security cfir cloud-security cloudsecurity dfir gcp-security incident-response kql microsoft microsoft-sentinel microsoftsentinel siem soc threat-hunting threat-intelligence

Last synced: 04 May 2025

https://github.com/zubux/badbucket

badbucket checks your s3 bucket for common misconfigurations

aws-s3 aws-security

Last synced: 06 Jul 2025

https://github.com/jtyers/aws-iam-utils

Python library for examining, creating and optimising IAM policies

aws aws-iam-policies aws-security iam python

Last synced: 14 Oct 2025

https://github.com/widdix/learn-iam-policy

Labs helping you to learn how write IAM policies following the least privilege principle.

aws aws-security iam iam-policy

Last synced: 24 Jun 2025

https://github.com/ets/aws-lambda-firewall

Securely and conveniently support IP address whitelists for your publicly routable services.

aws aws-apigateway aws-lambda aws-security

Last synced: 15 Apr 2025

https://github.com/mybuilder/aws-waf-logger

Log all AWS WAF Matched Rules to S3 and/or Loggly using Serverless

aws-lambda aws-security aws-waf lambda

Last synced: 15 Apr 2025

https://github.com/mitre/aws-s3-baseline

A micro InSpec baseline to check for insecure or public s3 buckets in your VPC

aws aws-s3-security aws-security inspec microprofile mitre-corporation mitre-inspec mitre-saf s3 s3-bucket s3-bucket-leak s3-security security

Last synced: 29 Jul 2025

https://github.com/iann0036/cfn-analyse

CloudFormation static analysis tool.

aws aws-security cloudformation

Last synced: 29 Jun 2025

https://github.com/DenizParlak/heimdall

AWS Attack Path Scanner - Discover privilege escalation paths across 10+ AWS services

aws aws-security cloud security

Last synced: 31 Jan 2026

https://github.com/nmasur/sgcontrol

Foolproof AWS security group management.

aws aws-security devops firewall python sysadmin yaml

Last synced: 16 May 2025

https://github.com/schnoddelbotz/cdn-securitygroup-sync

Automates sync of AWS security groups with your CDN provider's CIDRs

akamai aws aws-lambda aws-security cdn cloudflare

Last synced: 30 Jul 2025

https://github.com/prasanna7401/cis-benchmarks-autoremediation-in-aws-organization

Perform near real-time "Automatic" remediation of CIS v1.4.0 NON-COMPLIANT resources in IAM, Storage, Monitoring, Logging, and Networking in an AWS Multi-account setup using Security Hub Findings

aws aws-security aws-security-hub cis-benchmark cloud-security compliance-automation security-automation

Last synced: 14 Apr 2025

https://github.com/pixielabs/jsecrets

jsecrets is a wrapper around AWS Secrets Manager for your JavaScript projects.

aws-secrets-manager aws-security express-js javascript

Last synced: 17 Jun 2025

https://github.com/bridgecrewio/aws-collect-unused-security-groups

Track unused security groups of an AWS account over period of time with control of the interval to sample the security groups

aws aws-security security-groups

Last synced: 19 Jun 2025

https://github.com/cyberroute/aws-security-posture

A comprehensive collection of Lambda functions for strengthening AWS account security through automated detection, notification, and remediation.

aws-lambda aws-security aws-serverless cloud-computing cloud-security nodejs typescript well-architected-framework

Last synced: 19 May 2026

https://github.com/Su1ph3r/Nubicustos

Cloud security intelligence platform with cross-tool integration — transform raw security scans into actionable intelligence across AWS, Azure, GCP, and Kubernetes

aws-security azure-security checkov cloud-security compliance cspm devsecops gcp-security kubernetes-security multi-cloud open-source-security prowler scoutsuite security-audit vulnerability-scanner

Last synced: 13 Feb 2026

https://github.com/jksprattler/aws-security

Scripts, demos, PoC's, etc related to AWS security topics

aws aws-iam aws-lambda aws-security python

Last synced: 23 Apr 2025

https://github.com/mitre/saf-lambda-function

(WIP) An AWS Lambda Function to run the SAF CLI as a function in your AWS VPC

aws-la aws-lambda aws-security mitre mitre-corporation mitre-saf saf-cli security-automation security-automation-framework serverless

Last synced: 07 Mar 2026

https://github.com/tocconsulting/lambda-security-scanner

AWS Lambda security scanner: 19 checks across 5 categories, secret detection in env vars, and compliance mapping for 10 frameworks (CIS, PCI DSS, HIPAA, SOC 2, ISO 27001, NIST). Multi-threaded scans with interactive HTML dashboards.

aws aws-security cis-benchmark cloud-security compliance cspm devsecops hipaa lambda nist pci-dss python security security-scanner serverless soc2

Last synced: 06 Jun 2026

https://github.com/mhweiner/brek

Brek is a structured, typed config loader for Node.js — ideal for dynamic environments and securely managing secrets like those in AWS Secrets Manager.

aws aws-lambda aws-parameter-store aws-secrets-manager aws-security config configuration configuration-management lambda lambda-functions loader typescript

Last synced: 24 Feb 2026

https://github.com/rudsarkar/port-monitor-aws

This repository is create for implement the cron with the PortMonitor to get public IP's open/filtered port scan result of specific AWS EC2 region on Slack

aws aws-security cron docker portmonitor

Last synced: 06 May 2026

https://github.com/spandey1296/letsupgrade-aws

Project: Building an IP server using EC2 instance of AWS technology in LetsUpgrade Training

aws aws-apigateway aws-lambda aws-security ec2-instances loadbalancer ngnix

Last synced: 27 Mar 2025

https://github.com/dmdhrumilmistry/file-validation

Validate File Content Type using AI/ML models for S3 file uploads using AWS lambda

aws-lambda aws-security file-upload hacking security

Last synced: 31 Dec 2025

https://github.com/epomatti/aws-inspector

Amazon Inspector vulnerability management

aws aws-inspector aws-security ec2 ecr lambda ssm systems-manager terraform

Last synced: 20 Apr 2026

https://github.com/kavehmz/aws-setup

Secure AWS Usage by Assume Role and 2FA

2fa 2factor assume-role aws aws-security

Last synced: 27 Apr 2026

https://github.com/dhammon/lambda-rasp

AWS Lambda runtime application self-protection (RASP). Free and opensource.

aws-security cloud-security lambda rasp serverless-security

Last synced: 30 Mar 2025

https://github.com/epomatti/aws-ec2-ha-cluster

EC2 running Auto Scaling Groups with Application Load Balancer

auto-scaling-group aws aws-security ec2 efs terraform

Last synced: 13 Apr 2026

https://github.com/epomatti/aws-rds-sm-rotation

AWS SM-stored credential rotation with RDS

aws aws-security go golang iam mysql rds secretsmanager terraform

Last synced: 13 Apr 2026