My cheatsheet notes to pentest AWS infrastructure
☆711Oct 17, 2022Updated 3 years ago
Alternatives and similar repositories for AWSome-Pentesting
Users that are interested in AWSome-Pentesting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Resources to learn cloud environment and pentesting the same, contains AWS, Azure, Google Cloud☆56Mar 7, 2022Updated 4 years ago
- Azure and AWS Attacks☆1,125Nov 25, 2022Updated 3 years ago
- Automating situational awareness for cloud penetration tests.☆2,510May 26, 2026Updated last month
- ☆760Aug 26, 2022Updated 3 years ago
- Awesome list of step by step techniques to achieve Remote Code Execution on various apps!☆1,948Oct 7, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆2,032May 20, 2025Updated last year
- RedEye is a visual analytic tool supporting Red & Blue Team operations☆2,760Oct 20, 2023Updated 2 years ago
- A tool to keep AWS pentests and red teams efficient, organized, and stealthy.☆96Dec 29, 2025Updated 6 months ago
- Tools & Interesting Things for RedTeam Ops☆2,288Feb 10, 2026Updated 4 months ago
- Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.☆1,601Mar 4, 2024Updated 2 years ago
- Text4Shell scanner for Burp Suite☆188Oct 27, 2022Updated 3 years ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,819Apr 6, 2026Updated 2 months ago
- ☆570Dec 7, 2022Updated 3 years ago
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆297Sep 22, 2024Updated last year
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS…☆1,565Apr 3, 2026Updated 3 months ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,262May 19, 2026Updated last month
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.☆2,104May 21, 2026Updated last month
- Azure Security Resources and Notes☆1,761Feb 17, 2026Updated 4 months ago
- RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.☆1,923Oct 29, 2025Updated 8 months ago
- ☆412Dec 14, 2023Updated 2 years ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆2,139Oct 1, 2025Updated 9 months ago
- 🛡️ Awesome Cloud Security Resources ⚔️☆2,460Mar 17, 2026Updated 3 months ago
- ☆1,722Aug 19, 2022Updated 3 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Discover and watch the latest cybersecurity conference talks. A curated archive of public security conference content.☆283May 27, 2026Updated last month
- Mind-Maps of Several Things☆2,709Jun 29, 2023Updated 3 years ago
- ☆243Nov 21, 2024Updated last year
- This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and …☆2,532Updated this week
- Monkey365 is an open-source security assessment tool for Microsoft 365, Azure, and Microsoft Entra ID. It helps security professionals id…☆1,300May 18, 2026Updated last month
- Offensive security and Penetration Testing TTP for Cloud based environment (AWS / Azure / GCP)☆352Mar 4, 2025Updated last year
- A cloud security tool to search and clean up unused AWS access keys, written in Go.☆52Sep 2, 2022Updated 3 years ago
- A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.☆399Jan 10, 2025Updated last year
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆1,476Aug 18, 2023Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Checklist for container security - devsecops practices☆1,617Sep 15, 2025Updated 9 months ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆6,668May 27, 2026Updated last month
- Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks☆63Aug 4, 2022Updated 3 years ago
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆2,706Jun 16, 2026Updated 2 weeks ago
- OSWE, OSEP, OSED, OSEE☆3,882Jan 2, 2026Updated 6 months ago
- A collection of scripts for assessing Microsoft Azure security☆2,398Mar 15, 2026Updated 3 months ago
- A cheat sheet that contains advanced queries for SQL Injection of all types.☆3,239May 13, 2023Updated 3 years ago