| description | Cloud security resources for AWS, Azure, Google Cloud, Microsoft 365, cloud hardening, cloud logging, and authorized cloud testing. |
|---|
This page is the cloud security hub for AWS, Microsoft Azure/Microsoft 365, Google Cloud, and multi-cloud tooling. Keep provider-specific administration, hardening, and authorized testing references here; move logging, SIEM, DFIR, password spraying, and general training resources to their dedicated sections when they are not cloud-specific.
Cloud logging and audit collection are maintained in Security Logging.
{% content-ref url="security-logging/logging-cloud.md" %} logging-cloud.md {% endcontent-ref %}
KQL and SIEM query examples belong with Blue Defense.
{% content-ref url="blue-defense/query-languages.md" %} query-languages.md {% endcontent-ref %}
Cloud posture assessment tools such as Prowler, ScoutSuite, and Cloudsplaining are also indexed with hardening resources.
{% content-ref url="blue-defense/device-hardening/" %} device-hardening {% endcontent-ref %}
Cloud training and certification resources belong in Training.
{% content-ref url="training/" %} training {% endcontent-ref %}
- Cloud Computing for Science and Engineering - Ian Foster and Dennis B. Gannon.
- Cloud Design Patterns - Microsoft architecture guidance for resilient cloud systems.
- Designing Distributed Systems - Free Microsoft ebook; account may be required.
- Multi-tenant Applications for the Cloud, 3rd Edition - Microsoft guide to multi-tenant application design.
- CloudSecDocs - Detailed references for cloud and container security.
- CloudSecWiki - Curated cloud security notes and hardening tips.
- ATT&CK for Cloud - MITRE Engenuity note on cloud technique coverage.
- SANS Cloud Security - Cloud security training and guidance. The old checklist URL now redirects to a broader SANS cloud landing page.
- CloudFrontier - Monitors internet-facing attack surface across AWS, GCP, Azure, DigitalOcean, and Oracle Cloud.
- Cloud Conformity Azure knowledge base - Trend Micro Cloud One Conformity replaced the old Cloud Conformity branding.
- Cloud Conformity AWS knowledge base - Trend Micro Cloud One Conformity AWS best-practice checks.
- Awesome Cloud PenTest - Large collection of offensive cloud tools and resources.
- Hacking the Cloud - Cloud pentesting methodology, tradecraft, and tooling.
- Cloud Pentest Cheatsheets - Cheatsheets for cloud provider testing workflows.
- Hacking: The Next Generation - Cloud Insecurity: Sharing the Cloud with Your Enemy, pg. 121
- cloudfox - Finds exploitable paths in unfamiliar AWS, Azure, GCP, and Kubernetes environments.
- cloud-enum - Enumerates public cloud resources from keywords.
- ScoutSuite - Multi-cloud security posture assessment and reporting.
- SkyArk - Discovers privileged entities in Azure and AWS.
- PMapper - Models AWS IAM principals and privilege escalation paths.
- GitOops - Finds lateral movement and privilege escalation paths in GitHub organizations through CI/CD and access-control abuse.
- cloudbrute - Discovers public cloud infrastructure, files, and apps.
- CloudSploit - Cloud security posture checks by Aqua. Treat this as a defensive CSPM project rather than an offensive framework.
- serverless-prey - Serverless functions for authorized introspection of cloud function runtimes.
- Azure documentation
- Microsoft Cloud Penetration Testing Rules of Engagement
- Microsoft Azure IP Ranges and Service Tags - Official source for Azure service tag JSON.
- Microsoft cloud security benchmark - Replaces older Azure Security Benchmark links.
- Azure AD deployment plans
- ATT&CK for Azure AD
- ATT&CK for Office 365
- reprise99 Azure security resources
- Awesome Azure Security
- Azure Network Security
- Common Azure security vulnerabilities - Rhino Security Labs.
- Top 20 Microsoft Azure Vulnerabilities and Misconfigurations - InfosecMatter.
- AADInternals OSINT - Tenant lookup and Azure AD OSINT. This also fits the OSINT domain/tenant workflow.
- The Developer's Guide to Azure - Free Microsoft Azure training.
- Awesome Azure Learning - Azure learning and certification resources.
- AZ-500 Azure Security Technologies labs
- Breaking and Pwning Apps and Servers on AWS and Azure
- Learn Azure in a Month of Lunches
- Azure for Architects, Third Edition - Account may be required.
- Azure Functions Succinctly - Syncfusion ebook.
- Azure CLI documentation
- Azure CLI cheatsheet
- Operator Handbook: Azure CLI - pg. 39
- Find whether a target organization has Azure AD:
https://login.microsoftonline.com/getuserrealm.srf?login=username@<victimorganization>.onmicrosoft.com&xml=1
- Azure Active Directory documentation
- Attacking and Defending the Microsoft Cloud
- AzureAD-Attack-Defense
Microsoft Sentinel was formerly named Azure Sentinel. Keep cloud SIEM architecture and logging under Security Logging; keep KQL references in Blue Defense.
- Microsoft Sentinel overview
- Microsoft Sentinel service page
- Microsoft Sentinel hunting queries
- Microsoft Sentinel notebooks
- Microsoft Sentinel To-Go
- KQL quick reference
- KQL cheat sheet
- Kqlmagic
- AzSentinel PowerShell module - Historical community module; verify current maintenance before building workflows around it.
Azure Security Center and Azure Defender are now part of Microsoft Defender for Cloud.
- Microsoft Defender for Cloud overview
- Microsoft Defender for Cloud repository
- Azure security basics: Log Analytics, Security Center, and Sentinel - Older naming, still useful as historical context.
- Detecting Microsoft 365 and Azure Active Directory backdoors - FireEye/Mandiant research.
- PayloadsAllTheThings - Azure Pentest
- Pentest Book - Azure
- Azure Testing guide
- Azure AD Introduction for Red Teamers
- Hacking Azure AD via Active Directory
- Utilizing Azure Services for Red Team Engagements - Older article; URL typo is preserved by the source.
- Blue Cloud of Death: Red Teaming Azure
- Azure AD Connect for Red Teamers
- Red Teaming Microsoft: AD leaks via Azure
- How to create a backdoor to Azure AD
- AzureHound collection
- Keys of the Kingdom: Playing God as Global Admin
- The Attacker's Guide to Azure AD Conditional Access
- Check for Azure blobs
- Abusing Azure AD SSO with the Primary Refresh Token
- Attacking Azure Cloud Shell
- Nuking all Azure Resource Groups under all Azure Subscriptions
- Privilege Escalation and Lateral Movement on Azure
- Privilege Escalation in Azure AD
- Azure privilege escalation via Azure API permissions abuse
- Making clouds rain RCE in Office 365
- Backdooring Azure applications
- Backdooring Office 365 and Active Directory
- Office 365 attacks: bypassing MFA and persistence
- Spoofing Microsoft 365 Like It's 1995
- Operator Handbook: Azure_Exploit - pg. 44
- BlobHunter - Scans Azure blob storage accounts for public blobs.
- o365recon - Retrieves O365 information with valid credentials.
- Get-AzureADPSPermissionGrants.ps1 - Lists delegated and application permission grants.
- PowerZure - Azure and Azure AD assessment and exploitation framework.
- MicroBurst - Azure discovery, auditing, and post-exploitation PowerShell toolkit.
- lava - Microsoft Azure exploitation framework.
- XMGoat - Azure misconfiguration lab.
- AADInternals - Azure AD and Microsoft 365 administration and assessment module.
- Stormspotter - Graphs Azure and Azure AD objects for red-team analysis.
- ROADtools - Azure AD framework including ROADrecon.
- adconnectdump - Azure AD Connect password extraction.
- TeamFiltration - Enumerates, sprays, exfiltrates, and backdoors O365/AAD accounts.
- Microsoft 365 password spraying belongs with Password Attacks:
{% content-ref url="red-offensive/testing-methodology/password-attacks.md" %} password-attacks.md {% endcontent-ref %}
- CRT - CrowdStrike Reporting Tool for Azure.
- AzureADRecon - Azure AD tenant reporting.
- azucar - Security auditing tool for Azure environments.
- AzureADAssessment - Azure AD tenant assessment tooling.
- AzureHunter - Azure and O365 threat hunting playbooks.
- Sparrow - CISA cloud forensics tool for M365/Azure account and application compromise.
- Hawk - PowerShell collection tool for O365 intrusion investigation.
- DFIR-O365RC - Collects Microsoft 365 logs for Business Email Compromise investigations.
- Azure AD Incident Response PowerShell Module
- AWS security study plan
- AWS documentation
- AWS documentation GitHub organization
- AWS IP ranges JSON
- amazon-ec2-user-guide
- AWS Well-Architected Framework
- AWS Security Reference Architecture examples
- AWS Security Hub CIS standards
- Finding evil in AWS
- Generating AWS security signals from CloudTrail
- Operator Handbook: AWS Terms - pg. 35
- AWS CLI
- AWS CLI getting started
- AWS CheatSheet
- Operator Handbook: AWS CLI - pg. 20
- AWS Customer Support Policy for Penetration Testing
- PayloadsAllTheThings - AWS Pentest
- AWS IAM explained for Red and Blue teams
- AWS S3 penetration testing - Rhino Security Labs.
- AWS Penetration Testing Part 1: S3 Buckets
- AWS Penetration Testing Part 2: S3, IAM, EC2
- Pentest Book - AWS
- AWS penetration testing guide
- Operator Handbook: AWS Tips and Tricks - pg. 20
- The Hacker Playbook 3: Cloud Recon and Enumeration - pg. 37
| AWS Service | Testing focus |
|---|---|
| EC2 | Public service exposure, OS vulnerabilities, instance metadata access, and STS credential paths. |
| S3 | Anonymous access, broad bucket policies, object ACLs, public snapshots, and authenticated-user exposure. |
| ELB/ALB | HTTP request smuggling and load-balancer parsing differences. |
| SNS/SQS | Misconfigured topics and queues that allow unauthorized subscribe, publish, or receive actions. |
| RDS/Aurora/Redshift | Public exposure, weak access controls, and snapshot sharing. |
| EBS | Public snapshots and leaked sensitive data. |
| Cognito Authentication | Self-signup, weak app-client settings, token handling, and missing advanced security features. |
- Bucket_finder - Finds and tests Amazon buckets.
- bucket-stream - Finds S3 buckets by watching certificate transparency logs.
- S3Scanner - Scans for open S3 buckets and dumps contents.
- Pacu - AWS exploitation framework for authorized testing.
- Pacu wiki
- Kali Pacu package
- Pacu overview
- Operator Handbook: Pacu - pg. 31
- Nimbostratus - AWS fingerprinting and exploitation.
- Operator Handbook: Nimbostratus - pg. 30
- weirdAAL - AWS Attack Library.
- Arsenal of AWS Tools
- Cloudsplaining - AWS IAM least-privilege assessment.
- Prowler - AWS security best-practice assessment, audits, IR, continuous monitoring, and hardening.
- CloudSploit - Cloud Security Posture Management checks.
- CloudMapper - AWS environment analysis.
- cloudtracker - Compares CloudTrail logs with IAM policies to find over-privileged roles and users.
- aws-recon - Multi-threaded AWS inventory collection.
- review-security-groups - Summarizes AWS Security Groups and visualizes rules.
- cloudtrail2sightings - Converts CloudTrail data to MITRE ATT&CK Sightings.
- aws_ir - AWS incident response utility.
- acquire-aws-ec2 - Captures EC2 instances during IR.
- Incident Response in AWS
- AWS threat hunting repo
- GCP cheat sheet
- Security controls and forensic analysis for GKE apps
- Pub/Sub quickstart CLI
- Google Cloud penetration testing rules
- Pentest Book - GCP
- gcp_security
- GCP IAM Privilege Escalation
- Hardening your GKE cluster
- Operator Handbook: GCP CLI - pg. 70
- Operator Handbook: GCP Exploit - pg. 75