Awesome AWS Security
Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security
1.6k stars334 forks160 entriesLast push Sep 14, 2026 (15 days ago)License GPL-3.0
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
AWS Whitepapers
One of the important whitepaper to understand an overview of AWS
Books
It's published by Puresec and it has a good overview on AWS Lambda Security Best Practices which we should follow
Very nice book in Progress, yet to release.
In 2 lists
A book which has real-world examples for Cloud Security. Must read book for any Cloud Security Professionals.
In 2 lists
An Apress book that discusses serverless security on AWS, Azure and Google Cloud.
Online Tutorials/Blogs/Presentations
Nice overview and quick run through AWS Security resources.
It was fun going through the blog. You can learn from this article too.
It will give a very good grip on how S3 buckets can be exploited. Lengthy but worth to go through.
Examples are based on cloudgoat.
This article will show you why you need to be extra careful when using AWS S3.
Written by Dwight Hohnstein from Rhino Security Labs.
In 2 lists
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
In 2 lists
Online Courses (Paid/Free)
Linkedin Learn by Lynn Langit
Nicely designed the learning path who wants to be an AWS Security Experts from Acloud.guru
Previously an instructor led training now released as free and open source courseware for Cloud Pentesters
FREE EKS Attack and Defense From Anjali & Divyanshu
Few Important tools that you should consider are:; 1.1 AWS IAM: AWS Identity and Access Management (IAM) enables you to manage access to AWS services and resources securely; 1.2 CloudWatch: CloudWatch is the AWS monitoring tool; 1.3 CloudTrail: AWS CloudTrail is a service that enables governance,…
Collection of all security category tools and products
In 4 lists
Collection of scripts and resources for DevSecOps and Automated Incident Response Security
Searches through git repositories for high entropy strings and secrets, digging deep into commit history
In 2 lists
Audit git repos for secrets
Open source demos, concept and guidance related to the AWS CIS Foundation framework.
Tool to check AWS S3 bucket permissions
Comprehensive AWS S3 security scanner that analyzes bucket configurations, policies, and access controls
Multi-Cloud Security Auditing Tool
In 4 lists
AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool.
In 3 lists
A vault for securely storing and accessing AWS credentials in development environments
In 4 lists
A collection of AWS penetration testing junk
In 2 lists
AWS Penetration Testing Toolkits
In 4 lists
AWS Auditing and Hardening tool
Analyze your AWS environments (Python)
A Central Control Plane for AWS Permissions and Access
Deploy, update, and stage your WAFs while managing them centrally via FMS.
In 3 lists
A Collection for AWS environment penetration testing methodology.
A collection of attacks/tactics/techniques that can use by offensive security professionals during cloud exploitation.
Automating situational awareness for cloud penetration tests
In 2 lists
Tool to find problems in identity-based and resource-based IAM policies
Serverless AWS solution for tracking IAM, STS, and Console sign-in activities across all regions using EventBridge and CloudTrail
Passive DNS-based discovery of S3 (and other cloud) buckets by resolving CNAMEs and IPs during recon—ideal for stealthy and early identification of cloud storage exposures
In 2 lists
Orchestrates 20+ security tools (Prowler, ScoutSuite, Checkov, CloudFox, Pacu, etc.) with unified findings, attack paths, and compliance
Open-source AWS security assessment platform with AI-powered analysis, Prowler integration, and automated CIS benchmark scanning. Built serverless with CDK, Lambda, and Step Functions
Open-source AWS security scanner that detects attack chains and generates remediation code. 80+ checks, CIS/SOC 2 compliance.
A simple Python package for refreshing AWS temporary credentials in boto3 automatically. Supports MFA, IoT, and custom auth flows.
In 2 lists
Open-source framework for security agents with live, read-only access to your infrastructure (connects to AWS, GCP, Azure, self-managed Kubernetes, GitHub and GitLab).
Security Practices and CTFs
Amazon AWS CTF challenge - Written by @0xdabbad00.
In 2 lists
Vulnerable by Design AWS infrastructure setup tool
In 3 lists
OWASP ServerlessGoat is a deliberately insecure realistic AWS Lambda serverless application maintained by OWASP for educational purposes.
OWASP WrongSecrets is a vulnerable app which shows you how to not store secrets. It covers code, Docker, Kubernetes, and AWS cloud bad practices.
In 2 lists
Previously an instructor led training now released as free and open source courseware for Cloud Pentesters
This is not exactly security part, but would be helpful to understand AWS with this workshop examples.
Library of all the attack scenarios on Amazon S3 and how to mitigate them, following a risk-based approach
Create your own vulnerable by design AWS penetration testing playground
Free browser-based labs on public S3 buckets, over-permissive IAM, long-lived access keys, instance metadata abuse, and privileged containers
AWS Security Bulletin Important Issues
(This issue may allow containers running on the same host, or adjacent hosts (hosts running in the same LAN or layer 2 domain), to reach TCP and UDP services bound to localhost (127.0.0.1))
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
In 4 lists
An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image…
AWS Security Podcast/Newsletter
Weekly Interviews with Cloud Security Professionals on AWS, Azure, GCP Security for Blue Teams & Red Teams
Weekly Cloud Security Nuggets in your inbox
Awesome AWS Security
Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security
AWS OverviewOne of the important whitepaper to understand an overview of AWS
Introduction to AWS Security WhitepaperAWS Well-Architected Security PillarIntroduction to Security By DesignAWS Well Architected FrameworkAWS Risk And Compliance WhitepaperAWS Security ChecklistAWS HIPAA Compliance WhitepaperAWS Cloud Adoption FrameworkAWS Auditing Security ChecklistAWS CIS Foundation benchmarkAWS Security Incident ResponseOverview of AWS Lambda SecurityAWS KMS Best PracticesEncrypting File Data with Amazon Elastic File SystemSecurity of AWS CloudHSM backupsSecurity overview of AWS LambdaNIST Cybersecurity Framework in the AWS cloudNIST 800-144 Security and Privacy in Public Cloud ComputingSecurity at the Edge: Core PrinciplesAWS KMS Best PracticesSecurity Overview of AWS FargateHands-On AWS Penetration Testing with Kali Linux by PackTMastering AWS Security by PackTSecurity Best Practices on AWS by PackTCloud Security AutomationAWS Automation CookbookAWS Lambda Security Best Practices - pdfIt's published by Puresec and it has a good overview on AWS Lambda Security Best Practices which we should follow
AWS Security by ManningVery nice book in Progress, yet to release.
Securing DevOpsA book which has real-world examples for Cloud Security. Must read book for any Cloud Security Professionals.
Serverless SecurityAn Apress book that discusses serverless security on AWS, Azure and Google Cloud.
AWS Security CookbookPractical Guide to Security in the AWS Cloud by SANS and sponsored by AWS Marketplace - pdfCSA Guide to Cloud Computing by SungressPractical Cloud Security by O'reillyEffective IAM for AWSAmazon Bedrock in ActionThe fundamentals of AWS SecurityYoutube
AWS Security by DesignYoutube
Account Security with IAMYoutube
AWS re:Inforce 2019 Security Best PracticesYoutube
AWS Cloud Security PlaylistYoutube
A cloud security architecture workshop by RSAYoutube
AWS Cloud SecurityOreilly
Introduction to AWS Security HubYoutube
Solution for flaws.cloud AWS Security ChallengeYoutube Playlist
Hands-On With AWS Security Best PracticesAWS re:Invent 2020: Security at scale: How Goldman Sachs manages network and access controlAWS Security official blogAWS in Plain EnglishWhy the CIA trusts AWSFundamentals of AWS SecurityPresentation from AWS
AWS Security primerNice overview and quick run through AWS Security resources.
How a whitehat hacker earned $1500 in 15 minutes due to AWS S3 misconfigurationIt was fun going through the blog. You can learn from this article too.
A deep dive into AWS S3 access controlIt will give a very good grip on how S3 buckets can be exploited. Lengthy but worth to go through.
How Federico hacked a whole EC2 network during a penetration testA short blog on hacking AWSExamples are based on cloudgoat.
S3 security is flawed by designThis article will show you why you need to be extra careful when using AWS S3.
51 Tips for Security AWS(pdf)McAfee
The role of API gateways in API securityFinding SSRF via HTML Injection inside a PDF file on AWS EC2Getting shell and data access in AWS by chaining vulnerabilitiesHacking Serverless Runtimes - Blackhat2017Detailed blog on ConsoleMe: A Central Control Plane for AWS Permissions and Access by NetflixStrengthen the security of sensitive data stored in Amazon S3 by using additional AWS servicesUse IMDSv2 instead: Defense in depthManaging permissions with grants in AWS Key Management ServiceAWS IAM ExploitationS3 Pentest by Rhino Security LabsWritten by Dwight Hohnstein from Rhino Security Labs.
How an Attacker Could Use Instance Metadata to Breach Your App in AWSOrca Security Research Team Discovers AWS CloudFormation VulnerabilityOrca Security Research Team Discovers AWS Glue VulnerabilityHow I Discovered Thousands of Open Databases on AWSCVE-2022-25165: Privilege Escalation to SYSTEM in AWS VPN ClientDownloading and Exploring AWS EBS SnapshotsWeaponizing AWS ECS Task Definitions to Steal Credentials From Running ContainersGood Read on AWS IAM Privilege Escalation – Methods and MitigationOne more on IAM Privilege EscalationA very good repo for learning IAM based vulnerabilitiesUse Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
AWS Penetration Testing: Step by step guideAWS Interview question on SSHAWS Fundamentals: Address Security RisksCoursera
Cloud Computing SecurityCoursera
AWS: Getting started with Cloud SecurityEdX
AWS Certified Security SpecialtyUdemy by Zeal Vora
AWS Certified Security SpecialtyFrom Acloud.guru
AWS Certified Security SpecialtyUdemy by Stephan Maarek
AWS Certified Security SpecialtyFrom WhizLabs
AWS Advanced SecurityUdemy
AWS Security PathAppSecEngineer
AWS for Architects: Advanced SecurityLinkedin Learn by Lynn Langit
Practical Event Driven Security with AWSAcloud.guru
Learning Path for AWS SecurityNicely designed the learning path who wants to be an AWS Security Experts from Acloud.guru
Cloud Hacking courseFrom NotSoSercure
Breaking and Pwning Apps and Servers in AWS and AzurePreviously an instructor led training now released as free and open source courseware for Cloud Pentesters
AWS Skill Builder platform security learning planAWS SkillBuilder
Cloud Security: AWS Edition Bootcamp by Pentester AcademyFrom Pentester Academy
EKS Goat: AWS EKS Security Masterclass by Anjali and DivyanshuFREE EKS Attack and Defense From Anjali & Divyanshu
AWS Security Products - OfficialFew Important tools that you should consider are:; 1.1 AWS IAM: AWS Identity and Access Management (IAM) enables you…
Arsenal of AWS Security ToolsCollection of all security category tools and products
AWS Security AutomationCollection of scripts and resources for DevSecOps and Automated Incident Response Security
truffleHogSearches through git repositories for high entropy strings and secrets, digging deep into commit history
gitleaksAudit git repos for secrets
AWS Security BenchmarkOpen source demos, concept and guidance related to the AWS CIS Foundation framework.
S3 InspectorTool to check AWS S3 bucket permissions
S3 Security ScannerComprehensive AWS S3 security scanner that analyzes bucket configurations, policies, and access controls
ScoutSuiteMulti-Cloud Security Auditing Tool
ProwlerAWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool.
AWS VaultA vault for securely storing and accessing AWS credentials in development environments
AWS PWNA collection of AWS penetration testing junk
PacuAWS Penetration Testing Toolkits
ZeusAWS Auditing and Hardening tool
Cloud MapperAnalyze your AWS environments (Python)
ConsoleMeA Central Control Plane for AWS Permissions and Access
AWS Firewall FactoryDeploy, update, and stage your WAFs while managing them centrally via FMS.
AWS Pentesting/Red Team Methodology - by hacktricksA Collection for AWS environment penetration testing methodology.
AWS Pentesting/Red Team Methodology - by hackingthe.cloudA collection of attacks/tactics/techniques that can use by offensive security professionals during cloud exploitation.
CloudFoxAutomating situational awareness for cloud penetration tests
aws-lint-iam-policiesTool to find problems in identity-based and resource-based IAM policies
IAM Activity TrackerServerless AWS solution for tracking IAM, STS, and Console sign-in activities across all regions using EventBridge and…
s3dnsPassive DNS-based discovery of S3 (and other cloud) buckets by resolving CNAMEs and IPs during recon—ideal for…
NubicustosOrchestrates 20+ security tools (Prowler, ScoutSuite, Checkov, CloudFox, Pacu, etc.) with unified findings, attack…
CloudSecureOpen-source AWS security assessment platform with AI-powered analysis, Prowler integration, and automated CIS…
cloud-auditOpen-source AWS security scanner that detects attack chains and generates remediation code. 80+ checks, CIS/SOC 2…
boto3-refresh-sessionA simple Python package for refreshing AWS temporary credentials in boto3 automatically. Supports MFA, IoT, and custom…
CynativeOpen-source framework for security agents with live, read-only access to your infrastructure (connects to AWS, GCP,…
AWS Well Architected Security LabsFlaws to learn common mistakes in AWS through challengeAmazon AWS CTF challenge - Written by @0xdabbad00.
Flaws2 focuses on AWS security concepts through various challenge levelsCloudGoat By Rhino Security LabsVulnerable by Design AWS infrastructure setup tool
OWASP ServerlessGoatOWASP ServerlessGoat is a deliberately insecure realistic AWS Lambda serverless application maintained by OWASP for…
OWASP WrongSecretsOWASP WrongSecrets is a vulnerable app which shows you how to not store secrets. It covers code, Docker, Kubernetes,…
AWS S3 CTF Challenges with solutionsAWS CTF with practical scenarioBreaking and Pwning Apps and Servers in AWS and AzurePreviously an instructor led training now released as free and open source courseware for Cloud Pentesters
AWS Workshop officialThis is not exactly security part, but would be helpful to understand AWS with this workshop examples.
AWS Security Workshopsby AWS
ThreatModel for Amazon S3Library of all the attack scenarios on Amazon S3 and how to mitigate them, following a risk-based approach
AWS Cloud Quest: Security RoleAWS Jam Journey: SecurityTryHackMe: Attacking and Defending AWSFree AWS Security LabsBlack Sky Cloud Labs from HTBCloudFoxableCreate your own vulnerable by design AWS penetration testing playground
RansomLeak Cloud Security TrainingFree browser-based labs on public S3 buckets, over-permissive IAM, long-lived access keys, instance metadata abuse,…
Container Networking Security Issue ([CVE-2020-8558])(This issue may allow containers running on the same host, or adjacent hosts (hosts running in the same LAN or layer 2…
Minimum Version of TLS 1.2 Required for FIPS Endpoints by March 31, 2021Unencrypted md5 plaintext hash in metadata in AWS S3 Crypto SDK for golangThis project hosts security advisories and their accompanying proof-of-concepts related to research conducted at…
CVE-2018-15869An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and…
How I Discovered Thousands of Open Databases on AWSAWS Security breaches - 2017200 million voters data leakA lesson in AWS Security
Imperva blames data breach on Stolen AWS API keysTesla's Amazon cloud account was hacked and used to mine cryptocurrency10 worst Amazon S3 breachesLion Air the Latest to Get Tripped Up by Misconfigured AWS S3Online Fashion App 21 buttons Exposes Financial Records of Top European Influencers due to S3 misconfigurationCapital One Cloud data breach due to S3 misconfigurationUtah COVID-19 testing service exposes 50,000 patients’ photo IDs, personal info on the webUS municipalities suffer data breach due to misconfigured Amazon S3 bucketsCloud Security Podcast - YouTubeWeekly Interviews with Cloud Security Professionals on AWS, Azure, GCP Security for Blue Teams & Red Teams
Cloud Security NewsletterWeekly Cloud Security Nuggets in your inbox