惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recorded Future
Recorded Future
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Troy Hunt's Blog
S
Security Archives - TechRepublic
S
Security @ Cisco Blogs
AI
AI
Schneier on Security
Schneier on Security
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
C
CERT Recently Published Vulnerability Notes
Spread Privacy
Spread Privacy
Help Net Security
Help Net Security
L
Lohrmann on Cybersecurity
The Hacker News
The Hacker News
Google DeepMind News
Google DeepMind News
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Security Latest
Security Latest
T
Tor Project blog
P
Privacy International News Feed
The Last Watchdog
The Last Watchdog
L
LINUX DO - 最新话题
D
DataBreaches.Net
W
WeLiveSecurity
H
Help Net Security
L
LangChain Blog
B
Blog RSS Feed
Scott Helme
Scott Helme
Hacker News: Ask HN
Hacker News: Ask HN
C
Cisco Blogs
Cloudbric
Cloudbric
Application and Cybersecurity Blog
Application and Cybersecurity Blog
O
OpenAI News
I
InfoQ
GbyAI
GbyAI
Project Zero
Project Zero
Blog — PlanetScale
Blog — PlanetScale
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
G
GRAHAM CLULEY
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 聂微东
美团技术团队
PCI Perspectives
PCI Perspectives
Y
Y Combinator Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

Show HN

暂无文章

GitHub - TocConsulting/aws-security-cards: Free, comprehensive security reference guides for every major AWS service. Attack vectors, misconfigurations, CLI commands, and detection indicators
CloudHackerF · 2026-06-15 · via Show HN

AWS Security Cards

75 AWS service security reference cards covering attack vectors, misconfigurations, enumeration commands, privilege escalation, persistence techniques, detection indicators, and defense recommendations.

Each card is available in three formats:

  • Markdown - readable on GitHub, easy to search and contribute
  • HTML - beautiful standalone dark-themed pages, open in any browser
  • PDF - print-ready, share with your team

Open source community project.


Security Cards

# Service Category Risk Markdown HTML PDF
1 AWS IAM Identity 9.5 MD HTML PDF
2 AWS STS Identity 9.5 MD HTML PDF
3 AWS Organizations Multi-Account 9.5 MD HTML PDF
4 AWS Secrets Manager Secrets 9.5 MD HTML PDF
5 AWS IAM Identity Center Identity 9.5 MD HTML PDF
6 AWS Redshift Data Warehouse 9.2 MD HTML PDF
7 AWS EC2 Compute 9.0 MD HTML PDF
8 AWS S3 Storage 9.0 MD HTML PDF
9 AWS EKS Kubernetes 9.0 MD HTML PDF
10 AWS RDS Database 9.0 MD HTML PDF
11 AWS CodeBuild & CodePipeline CI/CD 9.0 MD HTML PDF
12 AWS Directory Service Identity 9.0 MD HTML PDF
13 AWS Glue ETL & Data Catalog 9.0 MD HTML PDF
14 AWS Route 53 DNS 9.0 MD HTML PDF
15 AWS Backup Disaster Recovery 9.0 MD HTML PDF
16 AWS CloudFormation Infrastructure as Code 9.0 MD HTML PDF
17 AWS CloudTrail Audit Logging 8.5 MD HTML PDF
18 AWS API Gateway API 8.5 MD HTML PDF
19 AWS ECR Container 8.5 MD HTML PDF
20 AWS ECS Containers 8.5 MD HTML PDF
21 AWS OpenSearch Search & Analytics 8.5 MD HTML PDF
22 AWS Systems Manager Management 8.5 MD HTML PDF
23 AWS SageMaker ML Platform 8.5 MD HTML PDF
24 AWS Step Functions Workflow Orchestration 8.5 MD HTML PDF
25 AWS Security Hub Security Posture 8.5 MD HTML PDF
26 AWS Transit Gateway Network Transit 8.5 MD HTML PDF
27 AWS DynamoDB Database 8.0 MD HTML PDF
28 AWS Cognito Identity 8.0 MD HTML PDF
29 AWS KMS Encryption 8.0 MD HTML PDF
30 AWS EBS Storage 8.0 MD HTML PDF
31 AWS AppSync Managed GraphQL 8.0 MD HTML PDF
32 AWS Athena SQL Query Service 8.0 MD HTML PDF
33 AWS DataSync Data Transfer 8.0 MD HTML PDF
34 AWS ElastiCache In-Memory Cache 8.0 MD HTML PDF
35 AWS EventBridge Event Bus 8.0 MD HTML PDF
36 AWS RAM Multi-Account 8.0 MD HTML PDF
37 AWS MSK Streaming 7.8 MD HTML PDF
38 AWS Lake Formation Data Lake 7.8 MD HTML PDF
39 AWS Batch Compute 7.5 MD HTML PDF
40 AWS Bedrock AI/ML 7.5 MD HTML PDF
41 AWS CloudFront CDN 7.5 MD HTML PDF
42 AWS CloudWatch Monitoring 7.5 MD HTML PDF
43 AWS Config Compliance & Configuration 7.5 MD HTML PDF
44 AWS EFS File Storage 7.5 MD HTML PDF
45 AWS Kinesis Streaming 7.5 MD HTML PDF
46 AWS Lambda Serverless 7.5 MD HTML PDF
47 AWS MemoryDB Redis 7.5 MD HTML PDF
48 AWS Transfer Family Managed File Transfer 7.5 MD HTML PDF
49 Amazon Macie Data Security 7.5 MD HTML PDF
50 AWS VPC Networking 7.0 MD HTML PDF
51 AWS GuardDuty Threat Detection 7.0 MD HTML PDF
52 AWS App Runner Containers 6.5 MD HTML PDF
53 AWS SQS Queuing 6.5 MD HTML PDF
54 AWS ELB/ALB Networking 6.0 MD HTML PDF
55 AWS Amplify Frontend 6.0 MD HTML PDF
56 AWS SNS Messaging 6.0 MD HTML PDF
57 Amazon Inspector V2 Vulnerability Scanning 6.0 MD HTML PDF
58 AWS ACM Certificates 5.5 MD HTML PDF
59 AWS Network Firewall Network 5.5 MD HTML PDF
60 AWS WAF Web Application Firewall 5.5 MD HTML PDF
61 AWS Control Tower Landing Zone Governance 9.5 MD HTML PDF
62 Amazon EMR Big Data / Analytics 8.0 MD HTML PDF
63 AWS Elastic Beanstalk Compute 8.0 MD HTML PDF
64 Amazon Lightsail Compute 8.0 MD HTML PDF
65 Amazon DocumentDB Database 8.0 MD HTML PDF
66 Amazon Neptune Graph Database 8.0 MD HTML PDF
67 Amazon QuickSight BI / Analytics 7.5 MD HTML PDF
68 Amazon WorkSpaces End-User Computing 7.5 MD HTML PDF
69 AWS Firewall Manager Central Security Management 7.5 MD HTML PDF
70 AWS CloudHSM Hardware Encryption 7.0 MD HTML PDF
71 AWS Shield DDoS Protection 7.0 MD HTML PDF
72 AWS X-Ray Distributed Tracing 7.0 MD HTML PDF
73 AWS Verified Access Zero Trust Networking 6.5 MD HTML PDF
74 Amazon Detective Security Investigation 6.0 MD HTML PDF
75 Amazon Verified Permissions Cedar Authorization 6.0 MD HTML PDF

What's in each card?

Every security card includes:

  1. Service Overview - How the service works, with attacker-relevant notes
  2. Risk Assessment - Numeric risk score with justification
  3. Attack Vectors - Known attack techniques and exploitation paths
  4. Common Misconfigurations - The mistakes that lead to breaches
  5. Enumeration Commands - AWS CLI commands for security assessment
  6. Privilege Escalation - How attackers escalate access
  7. Persistence Techniques - How attackers maintain access
  8. Detection Indicators - What to look for in logs and monitoring
  9. Exploitation Commands - Practical commands for authorized testing
  10. Policy Examples - Good vs. bad IAM/resource policies side-by-side
  11. Defense Recommendations - Hardening steps with CLI examples

Usage

Browse on GitHub: Click any Markdown link above to read directly on GitHub.

Open HTML locally: Clone the repo and open any HTML file in your browser for the full dark-themed experience.

Download PDFs: Each card is available as a print-ready PDF with embedded images and AWS icons.

Disclaimer

These security cards are for authorized security testing and educational purposes only. Always obtain proper authorization before testing. The attack techniques described should only be used in legitimate security assessments, CTF competitions, or defensive security research.

License

This project is open source. See LICENSE for details.

Contributing

Contributions are welcome! Feel free to submit PRs to improve existing cards, fix errors, or add new AWS services.