# dafthack/cloudpentestcheatsheets

**Attribution required: if you use, quote, or summarise this content, you must credit and link back to [awesome-repositories.com](https://awesome-repositories.com/repository/dafthack-cloudpentestcheatsheets).**

2,802 stars · 557 forks · mit

## Links

- GitHub: https://github.com/dafthack/CloudPentestCheatsheets
- awesome-repositories: https://awesome-repositories.com/repository/dafthack-cloudpentestcheatsheets.md

## Description

CloudPentestCheatsheets is a knowledge base and curated set of technical instructions for executing penetration tests on cloud-native architecture. It serves as a security audit guide and cheat sheet for auditing security and identifying misconfigurations across major cloud environments.

The project provides structured materials for performing cloud penetration testing, security auditing, and asset enumeration. These resources are organized to support multi-cloud security assessments through the evaluation of offensive security postures across various cloud service providers.

The technical guidance is delivered via modular provider segmentation and a checklist-driven workflow. It utilizes curated command libraries and a markdown-based flat-file organization to store instructional content and provider-specific commands.

## Tags

### DevOps & Infrastructure

- [Cloud Security Assessors](https://awesome-repositories.com/f/devops-infrastructure/cloud-infrastructure/cloud-computing-serverless/development-deployment-environments/cloud-deployment/cloud-infrastructure-providers/cloud-security-assessors.md) — Evaluates cloud environments for misconfigured resources and overly permissive settings across major providers. ([source](https://cdn.jsdelivr.net/gh/dafthack/cloudpentestcheatsheets@master/README.md))

### Part of an Awesome List

- [Security Command Collections](https://awesome-repositories.com/f/awesome-lists/devtools/shell-command-organizers/security-command-collections.md) — Organizes provider-specific CLI commands into categorized lists to streamline the enumeration of cloud infrastructure.
- [Cloud Security](https://awesome-repositories.com/f/awesome-lists/security/cloud-security.md) — Reference guides for cloud penetration testing techniques.

### Data & Databases

- [Cloud Asset Discoverers](https://awesome-repositories.com/f/data-databases/asset-inventory-management/cloud-asset-discoverers.md) — Provides a curated set of commands and checklists to identify and list cloud infrastructure resources. ([source](https://github.com/dafthack/CloudPentestCheatsheets/tree/master/cheatsheets/))

### Education & Learning Resources

- [Cloud Pentesting Knowledge Bases](https://awesome-repositories.com/f/education-learning-resources/cloud-pentesting-knowledge-bases.md) — Provides a structured collection of checklists and commands for auditing security and identifying cloud misconfigurations.
- [Cloud Service Reference Guides](https://awesome-repositories.com/f/education-learning-resources/cloud-service-reference-guides.md) — Provides technical reference materials for enumerating assets and testing offensive security postures across cloud providers.
- [Security Audit Workflows](https://awesome-repositories.com/f/education-learning-resources/engineering-checklists/automated-validation-checklists/security-audit-workflows.md) — Provides structured sequences of verification steps for systematically identifying security flaws in cloud environments.

### Security & Cryptography

- [Penetration Testing Suites](https://awesome-repositories.com/f/security-cryptography/security/utilities/security-tools/offensive-red-team/offensive-security-frameworks/penetration-testing-suites.md) — Provides a curated collection of tools and commands for executing structured offensive security tests on cloud services.
- [Command Execution Cheat Sheets](https://awesome-repositories.com/f/security-cryptography/vulnerability-assessment-testing/security-testing-auditing/security-testing/command-execution-cheat-sheets.md) — Ships as a reference guide for shell commands and payload execution techniques tailored for cloud penetration testing.

### Content Management & Publishing

- [Version-Controlled Knowledge Bases](https://awesome-repositories.com/f/content-management-publishing/content-management-systems/content-architecture-modeling/document-architectures/version-controlled-knowledge-bases.md) — Utilizes a version-controlled knowledge base to store and track technical instructional content.
- [Markdown Content Structures](https://awesome-repositories.com/f/content-management-publishing/content-management-systems/content-architecture-modeling/markdown-ecosystem-tools/markdown-content-structures.md) — Structures technical security guidance using hierarchical Markdown files for navigable documentation.

### Software Engineering & Architecture

- [Vendor-Specific Guidance Segments](https://awesome-repositories.com/f/software-engineering-architecture/modular-provider-interfaces/cloud-provider-mappings/vendor-specific-guidance-segments.md) — Separates security guidance by cloud vendor to allow targeted navigation of environment-specific misconfigurations.
