My cheatsheet notes to pentest AWS infrastructure
☆706Oct 17, 2022Updated 3 years ago
Alternatives and similar repositories for AWSome-Pentesting
Users that are interested in AWSome-Pentesting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Resources to learn cloud environment and pentesting the same, contains AWS, Azure, Google Cloud☆56Mar 7, 2022Updated 4 years ago
- Azure and AWS Attacks☆1,119Nov 25, 2022Updated 3 years ago
- Automating situational awareness for cloud penetration tests.☆2,370Apr 21, 2026Updated last week
- ☆761Aug 26, 2022Updated 3 years ago
- Awesome list of step by step techniques to achieve Remote Code Execution on various apps!☆1,948Oct 7, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆2,006May 20, 2025Updated 11 months ago
- RedEye is a visual analytic tool supporting Red & Blue Team operations☆2,746Oct 20, 2023Updated 2 years ago
- A tool to keep AWS pentests and red teams efficient, organized, and stealthy.☆96Dec 29, 2025Updated 4 months ago
- Tools & Interesting Things for RedTeam Ops☆2,271Feb 10, 2026Updated 2 months ago
- Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.☆1,588Mar 4, 2024Updated 2 years ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,812Apr 6, 2026Updated 3 weeks ago
- ☆571Dec 7, 2022Updated 3 years ago
- Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS…☆1,555Apr 3, 2026Updated last month
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆296Sep 22, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,166Apr 27, 2026Updated last week
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.☆2,066Jul 12, 2025Updated 9 months ago
- Azure Security Resources and Notes☆1,741Feb 17, 2026Updated 2 months ago
- RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.☆1,910Oct 29, 2025Updated 6 months ago
- ☆412Dec 14, 2023Updated 2 years ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,944Oct 1, 2025Updated 7 months ago
- 🛡️ Awesome Cloud Security Resources ⚔️☆2,402Mar 17, 2026Updated last month
- ☆1,717Aug 19, 2022Updated 3 years ago
- Mind-Maps of Several Things☆2,651Jun 29, 2023Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆243Nov 21, 2024Updated last year
- This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and …☆2,513Apr 20, 2026Updated 2 weeks ago
- Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Microsoft E…☆1,274Apr 15, 2026Updated 2 weeks ago
- Offensive security and Penetration Testing TTP for Cloud based environment (AWS / Azure / GCP)☆349Mar 4, 2025Updated last year
- A cloud security tool to search and clean up unused AWS access keys, written in Go.☆52Sep 2, 2022Updated 3 years ago
- A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.☆401Jan 10, 2025Updated last year
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆1,473Aug 18, 2023Updated 2 years ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆6,596Jan 18, 2026Updated 3 months ago
- Checklist for container security - devsecops practices☆1,618Sep 15, 2025Updated 7 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks☆64Aug 4, 2022Updated 3 years ago
- OSWE, OSEP, OSED, OSEE☆3,813Jan 2, 2026Updated 4 months ago
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆2,652Apr 6, 2026Updated 3 weeks ago
- A collection of scripts for assessing Microsoft Azure security☆2,374Mar 15, 2026Updated last month
- A cheat sheet that contains advanced queries for SQL Injection of all types.☆3,171May 13, 2023Updated 2 years ago
- CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool☆3,554Apr 27, 2026Updated last week
- ☆903Mar 17, 2026Updated last month