Cloud Security/AWS Security
AWS Security Platform

AWS Security
Knowledge Base & Tools

Deep-dive AWS security covering misconfigurations, attack paths, IAM privilege escalation, threat hunting queries, serverless threats, and incident response — with interactive tools for every scenario.

9
Tools
25+
PrivEsc Paths
CIS v2
Benchmark
MITRE
ATT&CK Cloud
IR
Playbooks
CRITPublic S3 bucket — most common cloud data breach vector| HIGHAWS keys in GitHub → IAM enum → privilege escalation to admin| CRITIMDSv1 + SSRF → EC2 role credential theft → account takeover| HIGHiam:PassRole + lambda:CreateFunction → instant admin escalation| MEDCloudTrail disabled → 47 days of undetected attacker activity| CRITOverprivileged Lambda execution role → project-wide access| HIGHCross-account role trust misconfiguration → account pivot| MEDECS task metadata endpoint → container escape → host creds| CRITPublic S3 bucket — most common cloud data breach vector| HIGHAWS keys in GitHub → IAM enum → privilege escalation to admin| CRITIMDSv1 + SSRF → EC2 role credential theft → account takeover| HIGHiam:PassRole + lambda:CreateFunction → instant admin escalation| MEDCloudTrail disabled → 47 days of undetected attacker activity| CRITOverprivileged Lambda execution role → project-wide access| HIGHCross-account role trust misconfiguration → account pivot| MEDECS task metadata endpoint → container escape → host creds|
Security Tools & Knowledge Base
Interactive⚠️

Misconfiguration Reference

S3, IAM, IMDS, Security Groups, CloudTrail — detect & fix the most dangerous AWS misconfigs.

S3IAMIMDSCloudTrail
Reference

AWS Security Checklist

CIS AWS Foundations Benchmark v2 mapped hardening controls — filter by category.

CIS BenchmarkHardening
Threat Hunting🔍

AWS Threat Hunting Queries

CloudTrail Athena SQL queries for IAM abuse, credential theft, exfil, and lateral movement.

CloudTrailAthena SQLSIEM
Interactive🗺️

Attack Path Visualiser

S3 → account takeover, SSRF chains, ransomware kill chains. Step-by-step attack paths.

S3SSRFRansomware
Interactive📋

IAM Policy Analyser

Paste policy JSON — get risk findings, wildcard actions, dangerous combos, and fixes.

IAMPolicy JSONLeast Privilege
Reference🚨

Cloud IR Checklist

AWS incident response playbooks — detection, containment, evidence, and eradication steps.

IR PlaybookContainmentForensics
Interactive📈

IAM Privilege Escalation

25 AWS + Azure + GCP escalation paths. Select starting permissions to find routes to admin.

25+ PathsAWSAzureGCP
Reference

Serverless Security Reference

Lambda threats, SSRF, secrets in env vars, supply chain, overprivileged roles, event injection.

LambdaSSRFSupply Chain
Interactive🎯

Cloud Pentest Checklist

Enumeration, IAM, network, data — AWS/Azure/GCP pentest checklist by phase and scope.

EnumerationIAMNetworkData

Tool