Skip to content

zer0-kr/awesome-DevOpsSec

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

36 Commits
ย 
ย 
ย 
ย 

Repository files navigation

๐Ÿ” Awesome DevOpsSec

Awesome License: MIT Stars

AWS ๋ฐ Kubernetes ๋ณด์•ˆ ๋ฆฌ์†Œ์Šค ํ๋ ˆ์ด์…˜

๋ธ”๋กœ๊ทธ, ๊ฐ€์ด๋“œ, ์•„ํ‹ฐํด, ์›Œํฌ์ˆ, ์ฑŒ๋ฆฐ์ง€, ๋„๊ตฌ๋ฅผ ํ•œ๊ณณ์— ๋ชจ์•˜์Šต๋‹ˆ๋‹ค.



๋ชฉ์ฐจ


๐Ÿ“ ๋ธ”๋กœ๊ทธ

๐Ÿ‡ฐ๐Ÿ‡ท ํ•œ๊ตญ์–ด

  • CloudNet@ Blog โ€” ํด๋ผ์šฐ๋“œ ๋„ค์ดํ‹ฐ๋ธŒ ๊ธฐ์ˆ  ๋ธ”๋กœ๊ทธ
  • MR.ZERO โ€” AWS ๋ณด์•ˆ ๋ฐ DevOps ๋ธ”๋กœ๊ทธ

๐Ÿ‡บ๐Ÿ‡ธ English

  • Rhino Security Labs Blog โ€” AWS ์นจํˆฌ ํ…Œ์ŠคํŠธ ์ „๋ฌธ ๋ธ”๋กœ๊ทธ
  • Hacking The Cloud โ€” ํด๋ผ์šฐ๋“œ ๊ณต๊ฒฉ ๊ธฐ๋ฒ• ๋ฐฑ๊ณผ์‚ฌ์ „
  • HackTricks Cloud โ€” AWS ํŽœํ…Œ์ŠคํŒ… ๊ฐ€์ด๋“œ

๐Ÿ“„ ๊ฐ€์ด๋“œ & ๋ฌธ์„œ

AWS

Kubernetes


๐Ÿ“ฐ ์•„ํ‹ฐํด

AWS

Kubernetes


๐Ÿงช ์›Œํฌ์ˆ

AWS

Kubernetes


๐Ÿšจ ์ทจ์•ฝ์  DB

  • CLOUDVULNDB โ€” ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค ์ทจ์•ฝ์  ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค
  • Public Cloud Security Breaches โ€” ๊ณต๊ฐœ๋œ ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์‚ฌ๊ณ  ๋ชจ์Œ
  • Cloud Security Attacks โ€” ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ๊ณต๊ฒฉ ๊ธฐ๋ฒ• ์ •๋ฆฌ
  • aws-customer-security-incidents โ€” AWS ๊ณ ๊ฐ ๋ณด์•ˆ ์‚ฌ๊ณ  ํƒ€์ž„๋ผ์ธ

๐ŸŽค ์ปจํผ๋Ÿฐ์Šค


๐Ÿดโ€โ˜ ๏ธ ์ฑŒ๋ฆฐ์ง€ & CTF

Goat ํ”„๋กœ์ ํŠธ

  • CloudGoat โ€” AWS ์ทจ์•ฝ ํ™˜๊ฒฝ ์‹œ๋ฎฌ๋ ˆ์ดํ„ฐ
  • KubernetesGoat โ€” K8s ์ทจ์•ฝ ํ™˜๊ฒฝ ์‹œ๋ฎฌ๋ ˆ์ดํ„ฐ
  • TerraGoat โ€” Terraform ์ทจ์•ฝ ์„ค์ • ๋ชจ์Œ

IAM

  • IAM Vulnerable โ€” IAM ๊ถŒํ•œ ์ƒ์Šน ์‹ค์Šต ํ™˜๊ฒฝ
  • The Big IAM Challenge โ€” IAM ์ •์ฑ… ๋ถ„์„ ์ฑŒ๋ฆฐ์ง€

ํ…Œ๋งˆ๋ณ„ ๊ฒŒ์ž„

  • S3 Game โ€” S3 ๋ณด์•ˆ ๊ฒŒ์ž„
  • EKS Game โ€” EKS ํด๋Ÿฌ์Šคํ„ฐ ํ•ดํ‚น ๊ฒŒ์ž„
  • K8s LAN Party โ€” K8s ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ ๊ฒŒ์ž„

Misconfigured

  • flAWS โ€” AWS ์„ค์ • ์˜ค๋ฅ˜ ์ฑŒ๋ฆฐ์ง€
  • flAWS2 โ€” flAWS ์‹œ์ฆŒ 2 (๊ณต๊ฒฉ์ž/๋ฐฉ์–ด์ž ์‹œ์ )
  • Sadcloud โ€” ์˜๋„์ ์œผ๋กœ ์ทจ์•ฝํ•œ AWS ์ธํ”„๋ผ
  • Vulnmachines โ€” ํด๋ผ์šฐ๋“œ ์ทจ์•ฝ์  ์‹ค์Šต ํ”Œ๋žซํผ
  • CI/CDon't โ€” CI/CD ํŒŒ์ดํ”„๋ผ์ธ ํ•ดํ‚น CTF

๐Ÿ“š ํŠธ๋ ˆ์ด๋‹


๐Ÿ› ๏ธ ๋„๊ตฌ

AWS

๋„๊ตฌ ์„ค๋ช…
prowler AWS/Azure/GCP ๋ณด์•ˆ ์ทจ์•ฝ์  ์Šค์บ๋„ˆ
steampipe API/์„œ๋น„์Šค ๋ฐ์ดํ„ฐ ์ง์ ‘ ์ฟผ๋ฆฌ (zero-ETL)
CloudSploit ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ํ˜•์ƒ ๊ด€๋ฆฌ (CSPM)
check_imds IMDSv1 ์‚ฌ์šฉ ์ธ์Šคํ„ด์Šค ์Šค์บ๋„ˆ
pacu AWS ์ต์Šคํ”Œ๋กœ์ž‡ ํ”„๋ ˆ์ž„์›Œํฌ
my-arsenal-of-aws-security-tools AWS ๋ณด์•ˆ ์˜คํ”ˆ์†Œ์Šค ๋„๊ตฌ ๋ชจ์Œ

Kubernetes

๋„๊ตฌ ์„ค๋ช…
Trivy ์ปจํ…Œ์ด๋„ˆ/K8s ์ทจ์•ฝ์ ยท์„ค์ •์˜ค๋ฅ˜ยท์‹œํฌ๋ฆฟ ์Šค์บ๋„ˆ
kube-bench CIS K8s ๋ฒค์น˜๋งˆํฌ ์ค€์ˆ˜ ๊ฒ€์‚ฌ
kube-hunter K8s ํด๋Ÿฌ์Šคํ„ฐ ๋ณด์•ˆ ์ทจ์•ฝ์  ํƒ์ƒ‰
managed-kubernetes-auditing-toolkit EKS ๋ณด์•ˆ ๊ฐ์‚ฌ ๋„๊ตฌ (DataDog)
Kubescape K8s ๋ณด์•ˆ ํ”Œ๋žซํผ (ํด๋Ÿฌ์Šคํ„ฐ/CIยทCD/IDE)
Falco ํด๋ผ์šฐ๋“œ ๋„ค์ดํ‹ฐ๋ธŒ ๋Ÿฐํƒ€์ž„ ๋ณด์•ˆ
Clair ์ปจํ…Œ์ด๋„ˆ ์ด๋ฏธ์ง€ ์ •์  ์ทจ์•ฝ์  ๋ถ„์„

๐Ÿ—‚๏ธ ๊ธฐํƒ€

  • ATT&CK โ€” MITRE ๊ณต๊ฒฉ ๊ธฐ๋ฒ• ํ”„๋ ˆ์ž„์›Œํฌ
  • D3FEND โ€” MITRE ๋ฐฉ์–ด ๊ธฐ๋ฒ• ํ”„๋ ˆ์ž„์›Œํฌ
  • RE&CT โ€” ์‚ฌ๊ณ  ๋Œ€์‘ ํ”„๋ ˆ์ž„์›Œํฌ

๊ธฐ์—ฌํ•˜๊ธฐ

๋ฆฌ์†Œ์Šค ์ถ”๊ฐ€, ๋งํฌ ์ˆ˜์ •, ์นดํ…Œ๊ณ ๋ฆฌ ์ œ์•ˆ ๋“ฑ ์–ด๋–ค ๊ธฐ์—ฌ๋“  ํ™˜์˜ํ•ฉ๋‹ˆ๋‹ค.

PR ๋˜๋Š” Issue๋กœ ์ œ์•ˆํ•ด ์ฃผ์„ธ์š”.


์ด ๋ฆฌ์ŠคํŠธ๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‹ค๋ฉด ์Šคํƒ€๋ฅผ ๋ˆŒ๋Ÿฌ์ฃผ์„ธ์š”!

Star on GitHub

About

Archiving for DevOpsSec resources

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors