Skip to main content

pentest-cloud-infrastructure

Cloud security posture management and container security assessment for AWS, Azure, GCP, and Kubernetes.

Source facts

Repository
jd-opensource/JoySafeter
Last source activity
February 11, 2026 at 09:17
Detected SKILL.md language
English
Stars
312
Forks
58

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

File Explorer
3 files

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
pentest-cloud-infrastructure
description
Cloud security posture management and container security assessment for AWS, Azure, GCP, and Kubernetes.
# Pentest Cloud Infrastructure ## Purpose Assess the security configuration of cloud environments and containerized infrastructure to detect misconfigurations, excessive permissions, and vulnerabilities. ## Core Workflow 1. **Cloud Config Audit**: Assess cloud provider configuration (AWS/Azure/GCP) using `prowler` and `scoutsuite`. 2. **IaC Scanning**: Analyze Infrastructure-as-Code (Terraform, CloudFormation) for security flaws using `checkov` and `terrascan`. 3. **Container Security**: Scan container images and runtime environments using `trivy`, `clair`, and `dockle`. 4. **Kubernetes Assessment**: Audit K8s clusters for CIS compliance and vulnerabilities using `kube-bench` and `kube-hunter`. 5. **Runtime Monitoring**: Analyze runtime behavior and rule violations using `falco`. ## References - `references/tools.md` - `references/workflows.md`
View on GitHub