817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Cloud Security GitHub Repositories
Explore popular GitHub repositories tagged “cloud-security”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
An encyclopedia for offensive and defensive security knowledge in cloud native technologies.
Automating situational awareness for cloud penetration tests.
🛡️ Awesome Cloud Security Resources ⚔️
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.
awesome cloud security 收集一些国内外不错的云安全资源,该项目主要面向国内的安全人员
The easiest way to access AWS.
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集
Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security
PacBot (Policy as Code Bot)
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
All-in-one Kubernetes access manager. User-level credentials, RBAC, SSO, audit logs.
Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
A Huge Learning Resources with Labs For Offensive Security Players
Awesome cloud enumerator
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks
SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS
Query, provision and operate Cloud, SaaS, API and Model Context Protocol (MCP) resources through a unified SQL-based framework for humans and AI agents.
Autonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.
Security Remediation Guides
opensecurity: open-source security and compliance. See and secure your cloud, containers, code, networks, deployments, devices. Define your rules, get precise checks, fix gaps fast. Streamlined audits. No fluff.
A curated list of awesome cloud security blogs, podcasts, standards, projects, and examples.
TerraformGoat is HXSecurity research lab's "Vulnerable by Design" multi cloud deployment tool.
文章 Attack Code 的详细全文。安全和开发总是具有伴生属性,尤其是云的安全方向,本篇文章是希望能帮助到读者的云安全入门材料。Full text of the article Attack Code. Security and development always have concomitant attributes, and this is especially true with the security direction of the cloud. This article is an introduction to cloud security that I hope will help readers.
Security interview questions with possible explanation for roles in AppSec, Pentesting, Cloud Security, DevSecOps, Network Security and so on