awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
dafthack avatar

dafthack/CloudPentestCheatsheets

0
View on GitHub↗
2,802 stars·557 forks·mit·8 views

CloudPentestCheatsheets

CloudPentestCheatsheets is a knowledge base and curated set of technical instructions for executing penetration tests on cloud-native architecture. It serves as a security audit guide and cheat sheet for auditing security and identifying misconfigurations across major cloud environments.

The project provides structured materials for performing cloud penetration testing, security auditing, and asset enumeration. These resources are organized to support multi-cloud security assessments through the evaluation of offensive security postures across various cloud service providers.

The technical guidance is delivered via modular provider segmentation and a checklist-driven workflow. It utilizes curated command libraries and a markdown-based flat-file organization to store instructional content and provider-specific commands.

Features

  • Cloud Security Assessors - Evaluates cloud environments for misconfigured resources and overly permissive settings across major providers.
  • Security Command Collections - Organizes provider-specific CLI commands into categorized lists to streamline the enumeration of cloud infrastructure.
  • Cloud Asset Discoverers - Provides a curated set of commands and checklists to identify and list cloud infrastructure resources.
  • Cloud Pentesting Knowledge Bases - Provides a structured collection of checklists and commands for auditing security and identifying cloud misconfigurations.
  • Cloud Service Reference Guides - Provides technical reference materials for enumerating assets and testing offensive security postures across cloud providers.
  • Security Audit Workflows - Provides structured sequences of verification steps for systematically identifying security flaws in cloud environments.
  • Penetration Testing Suites - Provides a curated collection of tools and commands for executing structured offensive security tests on cloud services.
  • Command Execution Cheat Sheets - Ships as a reference guide for shell commands and payload execution techniques tailored for cloud penetration testing.
  • Version-Controlled Knowledge Bases - Utilizes a version-controlled knowledge base to store and track technical instructional content.
  • Markdown Content Structures - Structures technical security guidance using hierarchical Markdown files for navigable documentation.
  • Vendor-Specific Guidance Segments - Separates security guidance by cloud vendor to allow targeted navigation of environment-specific misconfigurations.
  • Cloud Security - Reference guides for cloud penetration testing techniques.

Star history

Star history chart for dafthack/cloudpentestcheatsheetsStar history chart for dafthack/cloudpentestcheatsheets

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to CloudPentestCheatsheets

Similar open-source projects, ranked by how many features they share with CloudPentestCheatsheets.
  • rhinosecuritylabs/pacuRhinoSecurityLabs avatar

    RhinoSecurityLabs/pacu

    5,234View on GitHub↗

    Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments. It serves as a cloud penetration testing tool and resource enumerator used to identify misconfigurations, map attack surfaces, and execute privilege escalation paths. The framework provides specialized capabilities for post-exploitation and red team operations, including establishing persistence through identity and access management backdooring. It distinguishes itself with a plugin-based module system that allows for the development of custom tasks and the orchestration of A

    Python
    View on GitHub↗5,234
  • jekil/awesome-hackingjekil avatar

    jekil/awesome-hacking

    3,746View on GitHub↗

    This project is a curated, version-controlled directory of software and resources designed for cybersecurity professionals and researchers. It functions as a centralized knowledge base that aggregates and organizes external security utilities into a structured taxonomy to facilitate discovery and access for specialized research and testing tasks. The repository distinguishes itself through a community-driven model where external resource locations are verified and maintained by contributors. By leveraging a distributed version control system, the project ensures the historical integrity and c

    Pythoncurated-listforensicshacking
    View on GitHub↗3,746
  • projectdiscovery/naabuprojectdiscovery avatar

    projectdiscovery/naabu

    5,766View on GitHub↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    View on GitHub↗5,766
  • swisskyrepo/payloadsallthethingsswisskyrepo avatar

    swisskyrepo/PayloadsAllTheThings

    78,434View on GitHub↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Pythonbountybugbountybypass
    View on GitHub↗78,434
See all 30 alternatives to CloudPentestCheatsheets→

Frequently asked questions

What does dafthack/cloudpentestcheatsheets do?

CloudPentestCheatsheets is a knowledge base and curated set of technical instructions for executing penetration tests on cloud-native architecture. It serves as a security audit guide and cheat sheet for auditing security and identifying misconfigurations across major cloud environments.

What are the main features of dafthack/cloudpentestcheatsheets?

The main features of dafthack/cloudpentestcheatsheets are: Cloud Security Assessors, Security Command Collections, Cloud Asset Discoverers, Cloud Pentesting Knowledge Bases, Cloud Service Reference Guides, Security Audit Workflows, Penetration Testing Suites, Command Execution Cheat Sheets.

What are some open-source alternatives to dafthack/cloudpentestcheatsheets?

Open-source alternatives to dafthack/cloudpentestcheatsheets include: rhinosecuritylabs/pacu — Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments.… jekil/awesome-hacking — This project is a curated, version-controlled directory of software and resources designed for cybersecurity… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… swisskyrepo/payloadsallthethings — This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers.… rohitg00/devops-interview-questions — This repository serves as a curated knowledge base and study resource for professionals preparing for technical… mishakorzik/allhackingtools — AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of…