My cheatsheet notes to pentest AWS infrastructure
☆704Oct 17, 2022Updated 3 years ago
Alternatives and similar repositories for AWSome-Pentesting
Users that are interested in AWSome-Pentesting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Resources to learn cloud environment and pentesting the same, contains AWS, Azure, Google Cloud☆56Mar 7, 2022Updated 4 years ago
- Azure and AWS Attacks☆1,116Nov 25, 2022Updated 3 years ago
- Automating situational awareness for cloud penetration tests.☆2,340Updated this week
- ☆758Aug 26, 2022Updated 3 years ago
- Awesome list of step by step techniques to achieve Remote Code Execution on various apps!☆1,944Oct 7, 2023Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆2,000May 20, 2025Updated 10 months ago
- RedEye is a visual analytic tool supporting Red & Blue Team operations☆2,744Oct 20, 2023Updated 2 years ago
- A tool to keep AWS pentests and red teams efficient, organized, and stealthy.☆96Dec 29, 2025Updated 3 months ago
- Tools & Interesting Things for RedTeam Ops☆2,265Feb 10, 2026Updated 2 months ago
- Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.☆1,587Mar 4, 2024Updated 2 years ago
- Text4Shell scanner for Burp Suite☆189Oct 27, 2022Updated 3 years ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,806Apr 6, 2026Updated last week
- ☆569Dec 7, 2022Updated 3 years ago
- Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS…☆1,541Apr 3, 2026Updated last week
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆295Sep 22, 2024Updated last year
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,128Mar 30, 2026Updated 2 weeks ago
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.☆2,061Jul 12, 2025Updated 9 months ago
- Azure Security Resources and Notes☆1,734Feb 17, 2026Updated last month
- RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.☆1,904Oct 29, 2025Updated 5 months ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,930Oct 1, 2025Updated 6 months ago
- ☆412Dec 14, 2023Updated 2 years ago
- 🛡️ Awesome Cloud Security Resources ⚔️☆2,388Mar 17, 2026Updated 3 weeks ago
- ☆1,718Aug 19, 2022Updated 3 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Discover and watch the latest cybersecurity conference talks. A curated archive of public security conference content.☆282Updated this week
- Mind-Maps of Several Things☆2,634Jun 29, 2023Updated 2 years ago
- This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and …☆2,494Apr 3, 2026Updated last week
- ☆243Nov 21, 2024Updated last year
- Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Microsoft E…☆1,262Mar 19, 2026Updated 3 weeks ago
- Offensive security and Penetration Testing TTP for Cloud based environment (AWS / Azure / GCP)☆349Mar 4, 2025Updated last year
- A cloud security tool to search and clean up unused AWS access keys, written in Go.☆52Sep 2, 2022Updated 3 years ago
- A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.☆401Jan 10, 2025Updated last year
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆1,473Aug 18, 2023Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Checklist for container security - devsecops practices☆1,617Sep 15, 2025Updated 6 months ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆6,565Jan 18, 2026Updated 2 months ago
- Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks☆64Aug 4, 2022Updated 3 years ago
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆2,625Apr 6, 2026Updated last week
- OSWE, OSEP, OSED, OSEE☆3,798Jan 2, 2026Updated 3 months ago
- A collection of scripts for assessing Microsoft Azure security☆2,344Mar 15, 2026Updated 3 weeks ago
- A cheat sheet that contains advanced queries for SQL Injection of all types.☆3,170May 13, 2023Updated 2 years ago