Skip to content
81

Awesome AWS Security

Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security

1.6k stars334 forks160 entriesLast push Sep 14, 2026 (15 days ago)License GPL-3.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

AWS Whitepapers

AWS Overview

One of the important whitepaper to understand an overview of AWS

Introduction to AWS Security Whitepaper

AWS Well-Architected Security Pillar

Introduction to Security By Design

AWS Well Architected Framework

AWS Risk And Compliance Whitepaper

AWS Security Checklist

AWS HIPAA Compliance Whitepaper

AWS Cloud Adoption Framework

AWS Auditing Security Checklist

AWS CIS Foundation benchmark

AWS Security Incident Response

Overview of AWS Lambda Security

AWS KMS Best Practices

Encrypting File Data with Amazon Elastic File System

Security of AWS CloudHSM backups

Security overview of AWS Lambda

NIST Cybersecurity Framework in the AWS cloud

NIST 800-144 Security and Privacy in Public Cloud Computing

Security at the Edge: Core Principles

AWS KMS Best Practices

Security Overview of AWS Fargate

Books

Hands-On AWS Penetration Testing with Kali Linux by PackT

Mastering AWS Security by PackT

Security Best Practices on AWS by PackT

Cloud Security Automation

AWS Automation Cookbook

AWS Lambda Security Best Practices - pdf

It's published by Puresec and it has a good overview on AWS Lambda Security Best Practices which we should follow

AWS Security by Manning

Very nice book in Progress, yet to release.

In 2 lists

Securing DevOps

A book which has real-world examples for Cloud Security. Must read book for any Cloud Security Professionals.

In 2 lists

Serverless Security

An Apress book that discusses serverless security on AWS, Azure and Google Cloud.

AWS Security Cookbook

Practical Guide to Security in the AWS Cloud by SANS and sponsored by AWS Marketplace - pdf

CSA Guide to Cloud Computing by Sungress

Practical Cloud Security by O'reilly

Effective IAM for AWS

Amazon Bedrock in Action

Videos

The fundamentals of AWS Security

Youtube

AWS Security by Design

Youtube

Account Security with IAM

Youtube

AWS re:Inforce 2019 Security Best Practices

Youtube

AWS Cloud Security Playlist

Youtube

A cloud security architecture workshop by RSA

Youtube

AWS Cloud Security

Oreilly

Introduction to AWS Security Hub

Youtube

Solution for flaws.cloud AWS Security Challenge

Youtube Playlist

Hands-On With AWS Security Best Practices

AWS re:Invent 2020: Security at scale: How Goldman Sachs manages network and access control

Online Tutorials/Blogs/Presentations

AWS Security official blog

In 2 lists

AWS in Plain English

Why the CIA trusts AWS

Fundamentals of AWS Security

Presentation from AWS

AWS Security primer

Nice overview and quick run through AWS Security resources.

How a whitehat hacker earned $1500 in 15 minutes due to AWS S3 misconfiguration

It was fun going through the blog. You can learn from this article too.

A deep dive into AWS S3 access control

It will give a very good grip on how S3 buckets can be exploited. Lengthy but worth to go through.

How Federico hacked a whole EC2 network during a penetration test

A short blog on hacking AWS

Examples are based on cloudgoat.

S3 security is flawed by design

This article will show you why you need to be extra careful when using AWS S3.

51 Tips for Security AWS(pdf)

McAfee

The role of API gateways in API security

Finding SSRF via HTML Injection inside a PDF file on AWS EC2

Getting shell and data access in AWS by chaining vulnerabilities

Hacking Serverless Runtimes - Blackhat2017

Detailed blog on ConsoleMe: A Central Control Plane for AWS Permissions and Access by Netflix

Strengthen the security of sensitive data stored in Amazon S3 by using additional AWS services

Use IMDSv2 instead: Defense in depth

Managing permissions with grants in AWS Key Management Service

AWS IAM Exploitation

S3 Pentest by Rhino Security Labs

Written by Dwight Hohnstein from Rhino Security Labs.

In 2 lists

How an Attacker Could Use Instance Metadata to Breach Your App in AWS

Orca Security Research Team Discovers AWS CloudFormation Vulnerability

Orca Security Research Team Discovers AWS Glue Vulnerability

How I Discovered Thousands of Open Databases on AWS

CVE-2022-25165: Privilege Escalation to SYSTEM in AWS VPN Client

Downloading and Exploring AWS EBS Snapshots

Weaponizing AWS ECS Task Definitions to Steal Credentials From Running Containers

Good Read on AWS IAM Privilege Escalation – Methods and Mitigation

One more on IAM Privilege Escalation

A very good repo for learning IAM based vulnerabilities

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

In 2 lists

AWS Penetration Testing: Step by step guide

AWS Interview question on SSH

Online Courses (Paid/Free)

AWS Fundamentals: Address Security Risks

Coursera

Cloud Computing Security

Coursera

AWS: Getting started with Cloud Security

EdX

AWS Certified Security Specialty

Udemy by Zeal Vora

AWS Certified Security Specialty

From Acloud.guru

AWS Certified Security Specialty

Udemy by Stephan Maarek

AWS Certified Security Specialty

From WhizLabs

AWS Advanced Security

Udemy

AWS Security Path

AppSecEngineer

AWS for Architects: Advanced Security

Linkedin Learn by Lynn Langit

Practical Event Driven Security with AWS

Acloud.guru

Learning Path for AWS Security

Nicely designed the learning path who wants to be an AWS Security Experts from Acloud.guru

Cloud Hacking course

From NotSoSercure

Breaking and Pwning Apps and Servers in AWS and Azure

Previously an instructor led training now released as free and open source courseware for Cloud Pentesters

AWS Skill Builder platform security learning plan

AWS SkillBuilder

Cloud Security: AWS Edition Bootcamp by Pentester Academy

From Pentester Academy

EKS Goat: AWS EKS Security Masterclass by Anjali and Divyanshu

FREE EKS Attack and Defense From Anjali & Divyanshu

Tools of Trade

AWS Security Products - Official

Few Important tools that you should consider are:; 1.1 AWS IAM: AWS Identity and Access Management (IAM) enables you to manage access to AWS services and resources securely; 1.2 CloudWatch: CloudWatch is the AWS monitoring tool; 1.3 CloudTrail: AWS CloudTrail is a service that enables governance,…

Arsenal of AWS Security Tools

Collection of all security category tools and products

In 4 lists

AWS Security Automation

Collection of scripts and resources for DevSecOps and Automated Incident Response Security

truffleHog

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

In 2 lists

gitleaks

Audit git repos for secrets

In 5 listsDetails

AWS Security Benchmark

Open source demos, concept and guidance related to the AWS CIS Foundation framework.

S3 Inspector

Tool to check AWS S3 bucket permissions

S3 Security Scanner

Comprehensive AWS S3 security scanner that analyzes bucket configurations, policies, and access controls

ScoutSuite

Multi-Cloud Security Auditing Tool

In 4 lists

Prowler

AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool.

In 3 lists

AWS Vault

A vault for securely storing and accessing AWS credentials in development environments

In 4 lists

AWS PWN

A collection of AWS penetration testing junk

In 2 lists

Pacu

AWS Penetration Testing Toolkits

In 4 lists

Zeus

AWS Auditing and Hardening tool

Cloud Mapper

Analyze your AWS environments (Python)

ConsoleMe

A Central Control Plane for AWS Permissions and Access

AWS Firewall Factory

Deploy, update, and stage your WAFs while managing them centrally via FMS.

In 3 lists

AWS Pentesting/Red Team Methodology - by hacktricks

A Collection for AWS environment penetration testing methodology.

AWS Pentesting/Red Team Methodology - by hackingthe.cloud

A collection of attacks/tactics/techniques that can use by offensive security professionals during cloud exploitation.

CloudFox

Automating situational awareness for cloud penetration tests

In 2 lists

aws-lint-iam-policies

Tool to find problems in identity-based and resource-based IAM policies

IAM Activity Tracker

Serverless AWS solution for tracking IAM, STS, and Console sign-in activities across all regions using EventBridge and CloudTrail

s3dns

Passive DNS-based discovery of S3 (and other cloud) buckets by resolving CNAMEs and IPs during recon—ideal for stealthy and early identification of cloud storage exposures

In 2 lists

Nubicustos

Orchestrates 20+ security tools (Prowler, ScoutSuite, Checkov, CloudFox, Pacu, etc.) with unified findings, attack paths, and compliance

CloudSecure

Open-source AWS security assessment platform with AI-powered analysis, Prowler integration, and automated CIS benchmark scanning. Built serverless with CDK, Lambda, and Step Functions

cloud-audit

Open-source AWS security scanner that detects attack chains and generates remediation code. 80+ checks, CIS/SOC 2 compliance.

In 4 listsDetails

boto3-refresh-session

A simple Python package for refreshing AWS temporary credentials in boto3 automatically. Supports MFA, IoT, and custom auth flows.

In 2 lists

Cynative

Open-source framework for security agents with live, read-only access to your infrastructure (connects to AWS, GCP, Azure, self-managed Kubernetes, GitHub and GitLab).

In 6 listsDetails

Security Practices and CTFs

AWS Well Architected Security Labs

Flaws to learn common mistakes in AWS through challenge

Amazon AWS CTF challenge - Written by @0xdabbad00.

In 2 lists

Flaws2 focuses on AWS security concepts through various challenge levels

CloudGoat By Rhino Security Labs

Vulnerable by Design AWS infrastructure setup tool

In 3 lists

OWASP ServerlessGoat

OWASP ServerlessGoat is a deliberately insecure realistic AWS Lambda serverless application maintained by OWASP for educational purposes.

OWASP WrongSecrets

OWASP WrongSecrets is a vulnerable app which shows you how to not store secrets. It covers code, Docker, Kubernetes, and AWS cloud bad practices.

In 2 lists

AWS S3 CTF Challenges with solutions

AWS CTF with practical scenario

Breaking and Pwning Apps and Servers in AWS and Azure

Previously an instructor led training now released as free and open source courseware for Cloud Pentesters

AWS Workshop official

This is not exactly security part, but would be helpful to understand AWS with this workshop examples.

AWS Security Workshops

by AWS

ThreatModel for Amazon S3

Library of all the attack scenarios on Amazon S3 and how to mitigate them, following a risk-based approach

AWS Cloud Quest: Security Role

AWS Jam Journey: Security

TryHackMe: Attacking and Defending AWS

Free AWS Security Labs

Black Sky Cloud Labs from HTB

CloudFoxable

Create your own vulnerable by design AWS penetration testing playground

RansomLeak Cloud Security Training

Free browser-based labs on public S3 buckets, over-permissive IAM, long-lived access keys, instance metadata abuse, and privileged containers

AWS Security Bulletin Important Issues

Container Networking Security Issue ([CVE-2020-8558])

(This issue may allow containers running on the same host, or adjacent hosts (hosts running in the same LAN or layer 2 domain), to reach TCP and UDP services bound to localhost (127.0.0.1))

Minimum Version of TLS 1.2 Required for FIPS Endpoints by March 31, 2021

Unencrypted md5 plaintext hash in metadata in AWS S3 Crypto SDK for golang

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

In 4 lists

CVE-2018-15869

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image…

How I Discovered Thousands of Open Databases on AWS

AWS Security Breaches

AWS Security breaches - 2017

200 million voters data leak

A lesson in AWS Security

Imperva blames data breach on Stolen AWS API keys

Tesla's Amazon cloud account was hacked and used to mine cryptocurrency

10 worst Amazon S3 breaches

Lion Air the Latest to Get Tripped Up by Misconfigured AWS S3

Online Fashion App 21 buttons Exposes Financial Records of Top European Influencers due to S3 misconfiguration

Capital One Cloud data breach due to S3 misconfiguration

Utah COVID-19 testing service exposes 50,000 patients’ photo IDs, personal info on the web

US municipalities suffer data breach due to misconfigured Amazon S3 buckets

AWS Security Podcast/Newsletter

Cloud Security Podcast - YouTube

Weekly Interviews with Cloud Security Professionals on AWS, Azure, GCP Security for Blue Teams & Red Teams

Cloud Security Newsletter

Weekly Cloud Security Nuggets in your inbox

See category
94

Awesome Mac

jaywcjlove/awesome-mac

 This project is dedicated to collecting high-quality macOS software and organizing them systematically by different categories for easy search and use.

Fresh★ 115k1316 entriesPushed today
91

Open Source Mac Os Apps

serhii-londar/open-source-mac-os-apps

🚀 Awesome list of open source applications for macOS. https://t.me/s/opensourcemacosapps

Fresh★ 51k700 entriesPushed 20 days ago
91

Awesome-Kubernetes

ramitsurana/awesome-kubernetes

A curated list for awesome kubernetes sources :ship::tada:

Fresh★ 16k47 entriesPushed 8 days ago
90

Awesome Nodejs

sindresorhus/awesome-nodejs

:zap: Delightful Node.js packages and resources [BECAUSE OF TOO MUCH SPAM AND LOW-QUALITY SUBMISSIONS, SUBMISSIONS ARE PAUSED TEMPORARILY]

Fresh★ 67k588 entriesPushed 28 days ago
90

Awesome Home Assistant

frenck/awesome-home-assistant

A curated list of amazingly awesome Home Assistant resources.

Fresh★ 8.5k312 entriesPushed 2 days ago
90

Awesome Ios

vsouza/awesome-ios

A curated list of awesome iOS ecosystem, including Objective-C and Swift Projects

Fresh★ 53k1812 entriesPushed 1 month ago