My cheatsheet notes to pentest AWS infrastructure
☆705Oct 17, 2022Updated 3 years ago
Alternatives and similar repositories for AWSome-Pentesting
Users that are interested in AWSome-Pentesting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Resources to learn cloud environment and pentesting the same, contains AWS, Azure, Google Cloud☆56Mar 7, 2022Updated 4 years ago
- Azure and AWS Attacks☆1,113Nov 25, 2022Updated 3 years ago
- Automating situational awareness for cloud penetration tests.☆2,320Mar 10, 2026Updated 2 weeks ago
- ☆757Aug 26, 2022Updated 3 years ago
- Awesome list of step by step techniques to achieve Remote Code Execution on various apps!☆1,941Oct 7, 2023Updated 2 years ago
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆1,984May 20, 2025Updated 10 months ago
- RedEye is a visual analytic tool supporting Red & Blue Team operations☆2,741Oct 20, 2023Updated 2 years ago
- A tool to keep AWS pentests and red teams efficient, organized, and stealthy.☆96Dec 29, 2025Updated 2 months ago
- Tools & Interesting Things for RedTeam Ops☆2,260Feb 10, 2026Updated last month
- Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.☆1,585Mar 4, 2024Updated 2 years ago
- Text4Shell scanner for Burp Suite☆189Oct 27, 2022Updated 3 years ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,807Sep 17, 2024Updated last year
- ☆569Dec 7, 2022Updated 3 years ago
- Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS…☆1,533Jan 28, 2026Updated last month
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆296Sep 22, 2024Updated last year
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,097Mar 17, 2026Updated last week
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.☆2,042Jul 12, 2025Updated 8 months ago
- Azure Security Resources and Notes☆1,717Feb 17, 2026Updated last month
- RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.☆1,900Oct 29, 2025Updated 4 months ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,908Oct 1, 2025Updated 5 months ago
- ☆412Dec 14, 2023Updated 2 years ago
- 🛡️ Awesome Cloud Security Resources ⚔️☆2,373Mar 17, 2026Updated last week
- ☆1,706Aug 19, 2022Updated 3 years ago
- Watch the latest awesome security talks around the globe☆281Feb 23, 2025Updated last year
- Mind-Maps of Several Things☆2,631Jun 29, 2023Updated 2 years ago
- This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and …☆2,478Dec 31, 2025Updated 2 months ago
- Offensive security and Penetration Testing TTP for Cloud based environment (AWS / Azure / GCP)☆348Mar 4, 2025Updated last year
- ☆242Nov 21, 2024Updated last year
- Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Microsoft E…☆1,249Updated this week
- A cloud security tool to search and clean up unused AWS access keys, written in Go.☆52Sep 2, 2022Updated 3 years ago
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆1,472Aug 18, 2023Updated 2 years ago
- A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.☆401Jan 10, 2025Updated last year
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆6,541Jan 18, 2026Updated 2 months ago
- Checklist for container security - devsecops practices☆1,613Sep 15, 2025Updated 6 months ago
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆2,585Mar 17, 2026Updated last week
- Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks☆64Aug 4, 2022Updated 3 years ago
- OSWE, OSEP, OSED, OSEE☆3,786Jan 2, 2026Updated 2 months ago
- A collection of scripts for assessing Microsoft Azure security☆2,326Mar 15, 2026Updated last week
- A cheat sheet that contains advanced queries for SQL Injection of all types.☆3,159May 13, 2023Updated 2 years ago