pentest-cloud-infrastructure
Cloud security posture management and container security assessment for AWS, Azure, GCP, and Kubernetes.
来源信息
- 仓库
- jd-opensource/JoySafeter
- 最近来源活动
- 2026年2月11日 09:17
- 检测到的 SKILL.md 语言
- 英语
- 星标
- 312
- 分支
- 58
安装方式
默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。
检查来源文件
决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。
文件资源管理器
3 个文件正在显示 SKILL.md
SKILL.md
来源说明 · 只读预览- name
- pentest-cloud-infrastructure
- description
- Cloud security posture management and container security assessment for AWS, Azure, GCP, and Kubernetes.
# Pentest Cloud Infrastructure
## Purpose
Assess the security configuration of cloud environments and containerized infrastructure to detect misconfigurations, excessive permissions, and vulnerabilities.
## Core Workflow
1. **Cloud Config Audit**: Assess cloud provider configuration (AWS/Azure/GCP) using `prowler` and `scoutsuite`.
2. **IaC Scanning**: Analyze Infrastructure-as-Code (Terraform, CloudFormation) for security flaws using `checkov` and `terrascan`.
3. **Container Security**: Scan container images and runtime environments using `trivy`, `clair`, and `dockle`.
4. **Kubernetes Assessment**: Audit K8s clusters for CIS compliance and vulnerabilities using `kube-bench` and `kube-hunter`.
5. **Runtime Monitoring**: Analyze runtime behavior and rule violations using `falco`.
## References
- `references/tools.md`
- `references/workflows.md`
在 GitHub 查看