For the complete documentation index, see llms.txt. This page is also available as Markdown.

Yellow - Cloud

Cloud security resources for AWS, Azure, Google Cloud, Microsoft 365, cloud hardening, cloud logging, and authorized cloud testing.

This page is the cloud security hub for AWS, Microsoft Azure/Microsoft 365, Google Cloud, and multi-cloud tooling. Keep provider-specific administration, hardening, and authorized testing references here; move logging, SIEM, DFIR, password spraying, and general training resources to their dedicated sections when they are not cloud-specific.

Cloud logging and audit collection are maintained in Security Logging.

Logging - Cloud

KQL and SIEM query examples belong with Blue Defense.

Query Languages

Cloud posture assessment tools such as Prowler, ScoutSuite, and Cloudsplaining are also indexed with hardening resources.

Device Auditing and Hardening

Cloud training and certification resources belong in Training.

Training and Resources

General Cloud

Cloud Basics and Design

Cloud Security and Hardening

Cloud Pentesting

  • Awesome Cloud PenTest - Large collection of offensive cloud tools and resources.

  • Hacking the Cloud - Cloud pentesting methodology, tradecraft, and tooling.

  • Cloud Pentest Cheatsheets - Cheatsheets for cloud provider testing workflows.

  • Hacking: The Next Generation - Cloud Insecurity: Sharing the Cloud with Your Enemy, pg. 121

Multi-Cloud Tools

  • cloudfox - Finds exploitable paths in unfamiliar AWS, Azure, GCP, and Kubernetes environments.

  • cloud-enum - Enumerates public cloud resources from keywords.

  • ScoutSuite - Multi-cloud security posture assessment and reporting.

  • SkyArk - Discovers privileged entities in Azure and AWS.

  • PMapper - Models AWS IAM principals and privilege escalation paths.

  • GitOops - Finds lateral movement and privilege escalation paths in GitHub organizations through CI/CD and access-control abuse.

  • cloudbrute - Discovers public cloud infrastructure, files, and apps.

  • CloudSploit - Cloud security posture checks by Aqua. Treat this as a defensive CSPM project rather than an offensive framework.

  • serverless-prey - Serverless functions for authorized introspection of cloud function runtimes.

Microsoft Azure and Microsoft 365

Basics

Azure Training

Azure CLI and Administration

Microsoft Sentinel and KQL

Microsoft Sentinel was formerly named Azure Sentinel. Keep cloud SIEM architecture and logging under Security Logging; keep KQL references in Blue Defense.

Microsoft Defender for Cloud

Azure Security Center and Azure Defender are now part of Microsoft Defender for Cloud.

Azure Pentesting Guides

Azure and Microsoft 365 Tools

Offensive

  • BlobHunter - Scans Azure blob storage accounts for public blobs.

  • o365recon - Retrieves O365 information with valid credentials.

  • Get-AzureADPSPermissionGrants.ps1 - Lists delegated and application permission grants.

  • PowerZure - Azure and Azure AD assessment and exploitation framework.

  • MicroBurst - Azure discovery, auditing, and post-exploitation PowerShell toolkit.

  • lava - Microsoft Azure exploitation framework.

  • XMGoat - Azure misconfiguration lab.

  • AADInternals - Azure AD and Microsoft 365 administration and assessment module.

  • Stormspotter - Graphs Azure and Azure AD objects for red-team analysis.

  • ROADtools - Azure AD framework including ROADrecon.

  • adconnectdump - Azure AD Connect password extraction.

  • TeamFiltration - Enumerates, sprays, exfiltrates, and backdoors O365/AAD accounts.

  • Microsoft 365 password spraying belongs with Password Attacks:

Password Attacks

Defensive and DFIR

AWS - Amazon Web Services

Basics

AWS CLI

AWS Pentesting Guides

AWS Services and Attack Surfaces

AWS Service
Testing focus

EC2

Public service exposure, OS vulnerabilities, instance metadata access, and STS credential paths.

S3

Anonymous access, broad bucket policies, object ACLs, public snapshots, and authenticated-user exposure.

ELB/ALB

HTTP request smuggling and load-balancer parsing differences.

SNS/SQS

Misconfigured topics and queues that allow unauthorized subscribe, publish, or receive actions.

RDS/Aurora/Redshift

Public exposure, weak access controls, and snapshot sharing.

EBS

Public snapshots and leaked sensitive data.

Cognito Authentication

Self-signup, weak app-client settings, token handling, and missing advanced security features.

AWS Tools

Offensive

Defensive, DFIR, and Hunting

AWS Training

Google Cloud

Guides and Reference

Last updated