惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 【当耐特】
Microsoft Azure Blog
Microsoft Azure Blog
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
爱范儿
爱范儿
L
LangChain Blog
IT之家
IT之家
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
Hugging Face - Blog
Hugging Face - Blog
G
Google Developers Blog
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
宝玉的分享
宝玉的分享
博客园 - 三生石上(FineUI控件)
D
DataBreaches.Net
Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Show HN

Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code.
GitHub - TocConsulting/aws-security-cards: Free, comprehe...
CloudHackerF · 2026-06-15 · via Show HN

AWS Security Cards

75 AWS service security reference cards covering attack vectors, misconfigurations, enumeration commands, privilege escalation, persistence techniques, detection indicators, and defense recommendations.

Each card is available in three formats:

  • Markdown - readable on GitHub, easy to search and contribute
  • HTML - beautiful standalone dark-themed pages, open in any browser
  • PDF - print-ready, share with your team

Open source community project.


Security Cards

# Service Category Risk Markdown HTML PDF
1 AWS IAM Identity 9.5 MD HTML PDF
2 AWS STS Identity 9.5 MD HTML PDF
3 AWS Organizations Multi-Account 9.5 MD HTML PDF
4 AWS Secrets Manager Secrets 9.5 MD HTML PDF
5 AWS IAM Identity Center Identity 9.5 MD HTML PDF
6 AWS Redshift Data Warehouse 9.2 MD HTML PDF
7 AWS EC2 Compute 9.0 MD HTML PDF
8 AWS S3 Storage 9.0 MD HTML PDF
9 AWS EKS Kubernetes 9.0 MD HTML PDF
10 AWS RDS Database 9.0 MD HTML PDF
11 AWS CodeBuild & CodePipeline CI/CD 9.0 MD HTML PDF
12 AWS Directory Service Identity 9.0 MD HTML PDF
13 AWS Glue ETL & Data Catalog 9.0 MD HTML PDF
14 AWS Route 53 DNS 9.0 MD HTML PDF
15 AWS Backup Disaster Recovery 9.0 MD HTML PDF
16 AWS CloudFormation Infrastructure as Code 9.0 MD HTML PDF
17 AWS CloudTrail Audit Logging 8.5 MD HTML PDF
18 AWS API Gateway API 8.5 MD HTML PDF
19 AWS ECR Container 8.5 MD HTML PDF
20 AWS ECS Containers 8.5 MD HTML PDF
21 AWS OpenSearch Search & Analytics 8.5 MD HTML PDF
22 AWS Systems Manager Management 8.5 MD HTML PDF
23 AWS SageMaker ML Platform 8.5 MD HTML PDF
24 AWS Step Functions Workflow Orchestration 8.5 MD HTML PDF
25 AWS Security Hub Security Posture 8.5 MD HTML PDF
26 AWS Transit Gateway Network Transit 8.5 MD HTML PDF
27 AWS DynamoDB Database 8.0 MD HTML PDF
28 AWS Cognito Identity 8.0 MD HTML PDF
29 AWS KMS Encryption 8.0 MD HTML PDF
30 AWS EBS Storage 8.0 MD HTML PDF
31 AWS AppSync Managed GraphQL 8.0 MD HTML PDF
32 AWS Athena SQL Query Service 8.0 MD HTML PDF
33 AWS DataSync Data Transfer 8.0 MD HTML PDF
34 AWS ElastiCache In-Memory Cache 8.0 MD HTML PDF
35 AWS EventBridge Event Bus 8.0 MD HTML PDF
36 AWS RAM Multi-Account 8.0 MD HTML PDF
37 AWS MSK Streaming 7.8 MD HTML PDF
38 AWS Lake Formation Data Lake 7.8 MD HTML PDF
39 AWS Batch Compute 7.5 MD HTML PDF
40 AWS Bedrock AI/ML 7.5 MD HTML PDF
41 AWS CloudFront CDN 7.5 MD HTML PDF
42 AWS CloudWatch Monitoring 7.5 MD HTML PDF
43 AWS Config Compliance & Configuration 7.5 MD HTML PDF
44 AWS EFS File Storage 7.5 MD HTML PDF
45 AWS Kinesis Streaming 7.5 MD HTML PDF
46 AWS Lambda Serverless 7.5 MD HTML PDF
47 AWS MemoryDB Redis 7.5 MD HTML PDF
48 AWS Transfer Family Managed File Transfer 7.5 MD HTML PDF
49 Amazon Macie Data Security 7.5 MD HTML PDF
50 AWS VPC Networking 7.0 MD HTML PDF
51 AWS GuardDuty Threat Detection 7.0 MD HTML PDF
52 AWS App Runner Containers 6.5 MD HTML PDF
53 AWS SQS Queuing 6.5 MD HTML PDF
54 AWS ELB/ALB Networking 6.0 MD HTML PDF
55 AWS Amplify Frontend 6.0 MD HTML PDF
56 AWS SNS Messaging 6.0 MD HTML PDF
57 Amazon Inspector V2 Vulnerability Scanning 6.0 MD HTML PDF
58 AWS ACM Certificates 5.5 MD HTML PDF
59 AWS Network Firewall Network 5.5 MD HTML PDF
60 AWS WAF Web Application Firewall 5.5 MD HTML PDF
61 AWS Control Tower Landing Zone Governance 9.5 MD HTML PDF
62 Amazon EMR Big Data / Analytics 8.0 MD HTML PDF
63 AWS Elastic Beanstalk Compute 8.0 MD HTML PDF
64 Amazon Lightsail Compute 8.0 MD HTML PDF
65 Amazon DocumentDB Database 8.0 MD HTML PDF
66 Amazon Neptune Graph Database 8.0 MD HTML PDF
67 Amazon QuickSight BI / Analytics 7.5 MD HTML PDF
68 Amazon WorkSpaces End-User Computing 7.5 MD HTML PDF
69 AWS Firewall Manager Central Security Management 7.5 MD HTML PDF
70 AWS CloudHSM Hardware Encryption 7.0 MD HTML PDF
71 AWS Shield DDoS Protection 7.0 MD HTML PDF
72 AWS X-Ray Distributed Tracing 7.0 MD HTML PDF
73 AWS Verified Access Zero Trust Networking 6.5 MD HTML PDF
74 Amazon Detective Security Investigation 6.0 MD HTML PDF
75 Amazon Verified Permissions Cedar Authorization 6.0 MD HTML PDF

What's in each card?

Every security card includes:

  1. Service Overview - How the service works, with attacker-relevant notes
  2. Risk Assessment - Numeric risk score with justification
  3. Attack Vectors - Known attack techniques and exploitation paths
  4. Common Misconfigurations - The mistakes that lead to breaches
  5. Enumeration Commands - AWS CLI commands for security assessment
  6. Privilege Escalation - How attackers escalate access
  7. Persistence Techniques - How attackers maintain access
  8. Detection Indicators - What to look for in logs and monitoring
  9. Exploitation Commands - Practical commands for authorized testing
  10. Policy Examples - Good vs. bad IAM/resource policies side-by-side
  11. Defense Recommendations - Hardening steps with CLI examples

Usage

Browse on GitHub: Click any Markdown link above to read directly on GitHub.

Open HTML locally: Clone the repo and open any HTML file in your browser for the full dark-themed experience.

Download PDFs: Each card is available as a print-ready PDF with embedded images and AWS icons.

Disclaimer

These security cards are for authorized security testing and educational purposes only. Always obtain proper authorization before testing. The attack techniques described should only be used in legitimate security assessments, CTF competitions, or defensive security research.

License

This project is open source. See LICENSE for details.

Contributing

Contributions are welcome! Feel free to submit PRs to improve existing cards, fix errors, or add new AWS services.