Yellow - Cloud
Cloud security resources for AWS, Azure, Google Cloud, Microsoft 365, cloud hardening, cloud logging, and authorized cloud testing.
This page is the cloud security hub for AWS, Microsoft Azure/Microsoft 365, Google Cloud, and multi-cloud tooling. Keep provider-specific administration, hardening, and authorized testing references here; move logging, SIEM, DFIR, password spraying, and general training resources to their dedicated sections when they are not cloud-specific.
Related Sections
Cloud logging and audit collection are maintained in Security Logging.
Logging - CloudKQL and SIEM query examples belong with Blue Defense.
Query LanguagesCloud posture assessment tools such as Prowler, ScoutSuite, and Cloudsplaining are also indexed with hardening resources.
Device Auditing and HardeningCloud training and certification resources belong in Training.
Training and ResourcesGeneral Cloud
Cloud Basics and Design
Cloud Computing for Science and Engineering - Ian Foster and Dennis B. Gannon.
Cloud Design Patterns - Microsoft architecture guidance for resilient cloud systems.
Designing Distributed Systems - Free Microsoft ebook; account may be required.
Multi-tenant Applications for the Cloud, 3rd Edition - Microsoft guide to multi-tenant application design.
CloudSecDocs - Detailed references for cloud and container security.
CloudSecWiki - Curated cloud security notes and hardening tips.
ATT&CK for Cloud - MITRE Engenuity note on cloud technique coverage.
Cloud Security and Hardening
SANS Cloud Security - Cloud security training and guidance. The old checklist URL now redirects to a broader SANS cloud landing page.
CloudFrontier - Monitors internet-facing attack surface across AWS, GCP, Azure, DigitalOcean, and Oracle Cloud.
Cloud Conformity Azure knowledge base - Trend Micro Cloud One Conformity replaced the old Cloud Conformity branding.
Cloud Conformity AWS knowledge base - Trend Micro Cloud One Conformity AWS best-practice checks.
Cloud Pentesting
Awesome Cloud PenTest - Large collection of offensive cloud tools and resources.
Hacking the Cloud - Cloud pentesting methodology, tradecraft, and tooling.
Cloud Pentest Cheatsheets - Cheatsheets for cloud provider testing workflows.
Hacking: The Next Generation - Cloud Insecurity: Sharing the Cloud with Your Enemy, pg. 121
Multi-Cloud Tools
cloudfox - Finds exploitable paths in unfamiliar AWS, Azure, GCP, and Kubernetes environments.
cloud-enum - Enumerates public cloud resources from keywords.
ScoutSuite - Multi-cloud security posture assessment and reporting.
SkyArk - Discovers privileged entities in Azure and AWS.
PMapper - Models AWS IAM principals and privilege escalation paths.
GitOops - Finds lateral movement and privilege escalation paths in GitHub organizations through CI/CD and access-control abuse.
cloudbrute - Discovers public cloud infrastructure, files, and apps.
CloudSploit - Cloud security posture checks by Aqua. Treat this as a defensive CSPM project rather than an offensive framework.
serverless-prey - Serverless functions for authorized introspection of cloud function runtimes.
Microsoft Azure and Microsoft 365
Basics
Microsoft Azure IP Ranges and Service Tags - Official source for Azure service tag JSON.
Microsoft cloud security benchmark - Replaces older Azure Security Benchmark links.
Common Azure security vulnerabilities - Rhino Security Labs.
Top 20 Microsoft Azure Vulnerabilities and Misconfigurations - InfosecMatter.
AADInternals OSINT - Tenant lookup and Azure AD OSINT. This also fits the OSINT domain/tenant workflow.
Azure Training
The Developer's Guide to Azure - Free Microsoft Azure training.
Awesome Azure Learning - Azure learning and certification resources.
Azure for Architects, Third Edition - Account may be required.
Azure Functions Succinctly - Syncfusion ebook.
Azure CLI and Administration
Operator Handbook: Azure CLI - pg. 39
Find whether a target organization has Azure AD:
https://login.microsoftonline.com/getuserrealm.srf?login=username@<victimorganization>.onmicrosoft.com&xml=1
Microsoft Sentinel and KQL
Microsoft Sentinel was formerly named Azure Sentinel. Keep cloud SIEM architecture and logging under Security Logging; keep KQL references in Blue Defense.
AzSentinel PowerShell module - Historical community module; verify current maintenance before building workflows around it.
Microsoft Defender for Cloud
Azure Security Center and Azure Defender are now part of Microsoft Defender for Cloud.
Azure security basics: Log Analytics, Security Center, and Sentinel - Older naming, still useful as historical context.
Detecting Microsoft 365 and Azure Active Directory backdoors - FireEye/Mandiant research.
Azure Pentesting Guides
Utilizing Azure Services for Red Team Engagements - Older article; URL typo is preserved by the source.
Operator Handbook: Azure_Exploit - pg. 44
Azure and Microsoft 365 Tools
Offensive
BlobHunter - Scans Azure blob storage accounts for public blobs.
o365recon - Retrieves O365 information with valid credentials.
Get-AzureADPSPermissionGrants.ps1 - Lists delegated and application permission grants.
PowerZure - Azure and Azure AD assessment and exploitation framework.
MicroBurst - Azure discovery, auditing, and post-exploitation PowerShell toolkit.
lava - Microsoft Azure exploitation framework.
XMGoat - Azure misconfiguration lab.
AADInternals - Azure AD and Microsoft 365 administration and assessment module.
Stormspotter - Graphs Azure and Azure AD objects for red-team analysis.
ROADtools - Azure AD framework including ROADrecon.
adconnectdump - Azure AD Connect password extraction.
TeamFiltration - Enumerates, sprays, exfiltrates, and backdoors O365/AAD accounts.
Microsoft 365 password spraying belongs with Password Attacks:
Defensive and DFIR
CRT - CrowdStrike Reporting Tool for Azure.
AzureADRecon - Azure AD tenant reporting.
azucar - Security auditing tool for Azure environments.
AzureADAssessment - Azure AD tenant assessment tooling.
AzureHunter - Azure and O365 threat hunting playbooks.
Sparrow - CISA cloud forensics tool for M365/Azure account and application compromise.
Hawk - PowerShell collection tool for O365 intrusion investigation.
DFIR-O365RC - Collects Microsoft 365 logs for Business Email Compromise investigations.
AWS - Amazon Web Services
Basics
Operator Handbook: AWS Terms - pg. 35
AWS CLI
Operator Handbook: AWS CLI - pg. 20
AWS Pentesting Guides
AWS S3 penetration testing - Rhino Security Labs.
Operator Handbook: AWS Tips and Tricks - pg. 20
The Hacker Playbook 3: Cloud Recon and Enumeration - pg. 37
AWS Services and Attack Surfaces
EC2
Public service exposure, OS vulnerabilities, instance metadata access, and STS credential paths.
S3
Anonymous access, broad bucket policies, object ACLs, public snapshots, and authenticated-user exposure.
ELB/ALB
HTTP request smuggling and load-balancer parsing differences.
SNS/SQS
Misconfigured topics and queues that allow unauthorized subscribe, publish, or receive actions.
RDS/Aurora/Redshift
Public exposure, weak access controls, and snapshot sharing.
EBS
Public snapshots and leaked sensitive data.
Cognito Authentication
Self-signup, weak app-client settings, token handling, and missing advanced security features.
AWS Tools
Offensive
Bucket_finder - Finds and tests Amazon buckets.
bucket-stream - Finds S3 buckets by watching certificate transparency logs.
S3Scanner - Scans for open S3 buckets and dumps contents.
Pacu - AWS exploitation framework for authorized testing.
Operator Handbook: Pacu - pg. 31
Nimbostratus - AWS fingerprinting and exploitation.
Operator Handbook: Nimbostratus - pg. 30
weirdAAL - AWS Attack Library.
Defensive, DFIR, and Hunting
Cloudsplaining - AWS IAM least-privilege assessment.
Prowler - AWS security best-practice assessment, audits, IR, continuous monitoring, and hardening.
CloudSploit - Cloud Security Posture Management checks.
CloudMapper - AWS environment analysis.
cloudtracker - Compares CloudTrail logs with IAM policies to find over-privileged roles and users.
aws-recon - Multi-threaded AWS inventory collection.
review-security-groups - Summarizes AWS Security Groups and visualizes rules.
cloudtrail2sightings - Converts CloudTrail data to MITRE ATT&CK Sightings.
aws_ir - AWS incident response utility.
acquire-aws-ec2 - Captures EC2 instances during IR.
AWS Training
Google Cloud
Guides and Reference
Operator Handbook: GCP CLI - pg. 70
Operator Handbook: GCP Exploit - pg. 75
Last updated