awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

13 个仓库

Awesome GitHub RepositoriesCloud Security Tools

Security assessment and scanning utilities for cloud environments.

Explore 13 awesome GitHub repositories matching part of an awesome list · Cloud Security Tools. Refine with filters or upvote what's useful.

Awesome Cloud Security Tools GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • projectdiscovery/naabuprojectdiscovery 的头像

    projectdiscovery/naabu

    5,766在 GitHub 上查看↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Feeds discovered cloud assets into scanning tools like httpx and nuclei for security assessment.

    Gocdn-exclusionhacktoberfestnmap
    在 GitHub 上查看↗5,766
  • cdk-team/cdkcdk-team 的头像

    cdk-team/CDK

    4,692在 GitHub 上查看↗

    CDK 是一套专门用于容器安全审计、容器逃逸利用和云基础设施渗透测试的工具集。它提供了一系列脚本和工具,旨在识别和利用容器运行时的漏洞,以突破隔离环境并在底层主机操作系统上执行命令。 该项目具有专门的 Docker 运行时利用套件,用于滥用 Docker API、procfs 和 cgroups 以获得未经授权的主机级访问。它包括通过 LXCFS、用户命名空间利用和主机磁盘挂载绕过隔离的特定技术,以及用于提取云元数据和审计服务帐户权限以在集群环境中提升权限的功能。 该工具包涵盖了广泛的安全审计功能,包括用于机密泄露和策略分析的 Kubernetes 集群审计、敏感文件和服务扫描,以及主机网络共享的检测。它还提供了用于建立反向 shell、在受限环境中部署有效载荷以及在最小容器内安装系统管理工具的实用程序。

    Container-focused penetration testing tool for cloud environments.

    Go
    在 GitHub 上查看↗4,692
  • sa7mon/s3scannersa7mon 的头像

    sa7mon/S3Scanner

    2,997在 GitHub 上查看↗

    S3Scanner is a security tool for auditing public access and misconfigured permissions across S3-compatible storage providers. It functions as a storage auditor and security scanner designed to identify open buckets, enumerate publicly accessible objects, and exfiltrate data from misconfigured cloud environments. The project is distinguished by its integration with message brokers, allowing it to consume target lists for large-scale cloud infrastructure audits. It also provides utilities for dumping the entire contents of misconfigured buckets to local directories and calculating the total siz

    Finds and scans open AWS S3 buckets for sensitive data.

    Goawsbugbountygcp
    在 GitHub 上查看↗2,997
  • bishopfox/cloudfoxBishopFox 的头像

    BishopFox/cloudfox

    2,444在 GitHub 上查看↗

    Automating situational awareness for cloud penetration tests.

    Automated cloud infrastructure security assessment and enumeration.

    Go
    在 GitHub 上查看↗2,444
  • uzju/cloud-bucket-leak-detection-toolsUzJu 的头像

    UzJu/Cloud-Bucket-Leak-Detection-Tools

    1,258在 GitHub 上查看↗

    六大云存储,泄露利用检测工具

    Detection tool for identifying leaked cloud storage buckets.

    Python
    在 GitHub 上查看↗1,258
  • dark-kinga/cloudtoolsdark-kingA 的头像

    dark-kingA/cloudTools

    1,154在 GitHub 上查看↗

    云资产管理工具 目前工具定位是云安全相关工具,目前是两个模块 云存储工具、云服务工具, 云存储工具主要是针对oss存储、查看、删除、上传、下载、预览等等 云服务工具主要是针对rds、服务器的管理,查看、执行命令、接管等等

    Management and security utility for cloud storage and services.

    在 GitHub 上查看↗1,154
  • bishopfox/cloudfoxableBishopFox 的头像

    BishopFox/cloudfoxable

    457在 GitHub 上查看↗

    Create your own vulnerable by design AWS penetration testing playground

    Vulnerable cloud environment for practicing security assessment techniques.

    Python
    在 GitHub 上查看↗457
  • redskycyber/cloud-securityredskycyber 的头像

    redskycyber/Cloud-Security

    301在 GitHub 上查看↗

    This Repo serves as a collection of shared security and penetration testing resources for the cloud.

    Collection of resources for securing cloud-based infrastructure.

    在 GitHub 上查看↗301
  • datadog/kubehoundD

    DataDog/KubeHound

    0在 GitHub 上查看↗

    Tool for mapping attack paths in Kubernetes clusters.

    在 GitHub 上查看↗0
  • 404tk/cloudtoolkit4

    404tk/cloudtoolkit

    0在 GitHub 上查看↗

    Toolkit for performing cloud-based penetration testing.

    在 GitHub 上查看↗0
  • rnalter/thundercloudR

    Rnalter/ThunderCloud

    0在 GitHub 上查看↗

    Vulnerability scanning tool for cloud environments.

    在 GitHub 上查看↗0
  • neargle/my-re0-k8s-securityN

    neargle/my-re0-k8s-security

    0在 GitHub 上查看↗

    Educational resources for Kubernetes security and defense.

    在 GitHub 上查看↗0
  • teamssix/cfT

    teamssix/cf

    0在 GitHub 上查看↗

    Exploitation framework for post-compromise cloud operations.

    在 GitHub 上查看↗0
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Cloud Security Tools

探索子标签

  • Asset Pipeline IntegrationsFeeds discovered cloud assets into scanning tools like httpx and nuclei for security assessment. **Distinct from Cloud Security Tools:** Distinct from Cloud Security Tools: focuses on piping discovered assets into downstream tools, not the tools themselves.