My cheatsheet notes to pentest AWS infrastructure
☆710Oct 17, 2022Updated 3 years ago
Alternatives and similar repositories for AWSome-Pentesting
Users that are interested in AWSome-Pentesting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Resources to learn cloud environment and pentesting the same, contains AWS, Azure, Google Cloud☆56Mar 7, 2022Updated 4 years ago
- Azure and AWS Attacks☆1,123Nov 25, 2022Updated 3 years ago
- Automating situational awareness for cloud penetration tests.☆2,421May 26, 2026Updated 2 weeks ago
- ☆760Aug 26, 2022Updated 3 years ago
- Awesome list of step by step techniques to achieve Remote Code Execution on various apps!☆1,947Oct 7, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆2,022May 20, 2025Updated last year
- RedEye is a visual analytic tool supporting Red & Blue Team operations☆2,753Oct 20, 2023Updated 2 years ago
- A tool to keep AWS pentests and red teams efficient, organized, and stealthy.☆96Dec 29, 2025Updated 5 months ago
- Tools & Interesting Things for RedTeam Ops☆2,281Feb 10, 2026Updated 4 months ago
- Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.☆1,596Mar 4, 2024Updated 2 years ago
- Text4Shell scanner for Burp Suite☆188Oct 27, 2022Updated 3 years ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,821Apr 6, 2026Updated 2 months ago
- ☆570Dec 7, 2022Updated 3 years ago
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆296Sep 22, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS…☆1,564Apr 3, 2026Updated 2 months ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,227May 19, 2026Updated 3 weeks ago
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.☆2,092May 21, 2026Updated 3 weeks ago
- Azure Security Resources and Notes☆1,751Feb 17, 2026Updated 3 months ago
- RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.☆1,919Oct 29, 2025Updated 7 months ago
- ☆412Dec 14, 2023Updated 2 years ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,989Oct 1, 2025Updated 8 months ago
- 🛡️ Awesome Cloud Security Resources ⚔️☆2,449Mar 17, 2026Updated 2 months ago
- ☆1,723Aug 19, 2022Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Discover and watch the latest cybersecurity conference talks. A curated archive of public security conference content.☆283May 27, 2026Updated 2 weeks ago
- Mind-Maps of Several Things☆2,708Jun 29, 2023Updated 2 years ago
- ☆242Nov 21, 2024Updated last year
- This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and …☆2,529Apr 20, 2026Updated last month
- Monkey365 is an open-source security assessment tool for Microsoft 365, Azure, and Microsoft Entra ID. It helps security professionals id…☆1,296May 18, 2026Updated 3 weeks ago
- Offensive security and Penetration Testing TTP for Cloud based environment (AWS / Azure / GCP)☆352Mar 4, 2025Updated last year
- A cloud security tool to search and clean up unused AWS access keys, written in Go.☆52Sep 2, 2022Updated 3 years ago
- A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.☆399Jan 10, 2025Updated last year
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆1,476Aug 18, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Checklist for container security - devsecops practices☆1,617Sep 15, 2025Updated 8 months ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆6,644May 27, 2026Updated 2 weeks ago
- Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks☆63Aug 4, 2022Updated 3 years ago
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆2,686May 26, 2026Updated 2 weeks ago
- OSWE, OSEP, OSED, OSEE☆3,867Jan 2, 2026Updated 5 months ago
- A collection of scripts for assessing Microsoft Azure security☆2,387Mar 15, 2026Updated 2 months ago
- A cheat sheet that contains advanced queries for SQL Injection of all types.☆3,225May 13, 2023Updated 3 years ago