CSA CCM
Cloud Security
IAM Permissions Guardrails
AWS IAM Permissions Guardrails https://aws-samples.github.io/aws-iam-permissions-guardrails/
A Cloud Security Roadmap Template
Some actionable advice that can be undertaken to establish a cloud security program aimed at protecting a cloud native, service provider agnostic, container-based, offering.
CloudGPT - Use ChatGPT to analyze AWS policies for vulnerabilities
CloudGPT - Use ChatGPT to analyze AWS policies for vulnerabilities - gpt.py
Cloud incident response: Frameworks and best practices | TechTarget
Read up on cloud incident response, including how it differs from traditional incident response, its benefits and challenges, best practices and more.
A New Incentive for Using AWS VPC Endpoints - Ermetic
If you haven’t been using VPC endpoints until now, AWS's two new condition keys should make you consider doing so
GitHub - hashishrajan/aws-scp-best-practice-policies: AWS SCP Best Practices
AWS SCP Best Practices. Contribute to hashishrajan/aws-scp-best-practice-policies development by creating an account on GitHub.
Cloud Security Podcast - YouTube
Cloud Security Podcast is a community first WEEKLY VIDEO PODCAST, where each week we interview CyberSecurity Leaders and Cloud Security Practitioners from around the world to help you learn How to and What's HOT in Cloud Security. Video Host: Ashish is a Chief Information Security Officer (CISO) who is passionate about helping people get Cloud Security jobs and help CyberSecurity professionals do their job better in Public Cloud. Before being a CISO, Ashish has been a Security Architect, SOC Manager, Cloud Security Engineer, Identity and Access Management Consultant, Pentester(for 1 month). Cloud Security Meetup We also hold global meetup events and conferences for Cloud Security enthusiast & practitioners. Cloud Security Academy Academy to learn unbiased multi-cloud disciplinary Cloud Security practices to help you succeed as a Cloud Security Practitioner. All the information is on www.cloudsecuritypodcast.tv SUBSCRIBE TO THE CHANNEL TO BE NOTIFIED OF THE NEXT EVENT
Cloud Security Resources - Nick Jones
Cloud Security Specialist, Principal Consultant & Cloudsec lead @ WithSecure
cloudsecurity | Zotero
GitHub - aquasecurity/cloudsploit: Cloud Security Posture Management (CSPM)
Cloud Security Posture Management (CSPM). Contribute to aquasecurity/cloudsploit development by creating an account on GitHub.
Steampipe | select * from cloud;
Steampipe is an open source tool to instantly query your cloud services (e.g. AWS, Azure, GCP and more) with SQL. No DB required.
GitHub - prowler-cloud/prowler: Prowler is an Open Source Security tool to perform Cloud Security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It contains hundreds of controls covering CIS, PCI-DSS, ISO27001, GDPR, HIPAA, FFIEC, SOC2, AWS FTR, ENS and custom security frameworks.
Prowler is an Open Source Security tool to perform Cloud Security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It contains hundre...
GitHub - Zeus-Labs/ZeusCloud: Open Source Cloud Security
Open Source Cloud Security. Contribute to Zeus-Labs/ZeusCloud development by creating an account on GitHub.
GitHub - nccgroup/ScoutSuite: Multi-Cloud Security Auditing Tool
Multi-Cloud Security Auditing Tool. Contribute to nccgroup/ScoutSuite development by creating an account on GitHub.
GitHub - 4ndersonLin/awesome-cloud-security: 🛡️ Awesome Cloud Security Resources ⚔️
🛡️ Awesome Cloud Security Resources ⚔️. Contribute to 4ndersonLin/awesome-cloud-security development by creating an account on GitHub.
GitHub - toniblyx/my-arsenal-of-aws-security-tools: List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc. - GitHub - toniblyx/my-arsenal-of-aws-security-tools: List of open source tools for AWS security: defensive, o...
Hacking The Cloud
The encyclopedia for offensive security in the cloud
The last S3 security document that we'll ever need, and how to use it - TrustOnCloud
2022-02 - We have launched ControlCatalog, a friendly UI for our in-depth ThreatModels.
AWS security assessment: what scanners are missing and how threat modeling may help you?
There are many tools available today that are designed to automate security checks. For example, here’s a good list of open-source AWS…
Cloud Security Guy
🤔 ABOUT CLOUD SECURITY GUY 😃
Hello ! I am Taimur Ijlal and I am a multi-award winning, information security leader with over 20 years of international experience in cyber-security and IT risk management in the fin-tech industry. I am currently based in London UK where I moved after being awarded a UK Global Talent ( Tech Nation Visa ) . This Youtube channel was created to share advice about Cloud Security , Cyber-Security careers and Artificial Intelligence risks.
MY PROGRAMS
==============
👨💻️ Interested in cyber security career coaching ? Check this : https://www.fiverr.com/taimur74/coach-you-on-how-to-succeed-in-your-cybersecurity-career
🇬🇧 Interested in moving to the UK under Tech Nation VISA ? Check this:
👉https://uk-global-talent.thinkific.com/courses/global-talent-visa
FOLLOW ME ON MEDIUM
======================
Ⓜ️ Follow me on Medium: 👉https://medium.com/@taimurcloud123
Cloud Security Table Top Exercises
Evaluate your response to these 20 cloud security scenarios covering logging, RBAC, malicious access, and more.