# AWS 安全卡
**75 张 AWS 服务安全参考卡**,涵盖攻击向量、误配置、枚举命令、权限提升、持久化技术、检测指标和防御建议。
每张卡片都提供三种格式:
- **Markdown** - 可在 GitHub 上阅读,易于搜索和贡献
- **HTML** - 美观的独立深色主题页面,在任何浏览器中打开
- **PDF** - 打印就绪,与团队分享
开源社区项目。
## 安全卡
| # | | 服务 | 类别 | 风险 | Markdown | HTML | PDF |
|---|--|---------|----------|------|----------|------|-----|
| 1 |

| AWS IAM | 身份 | 9.5 | [MD](cards/markdown/iam.md) | [HTML](cards/html/iam.html) | [PDF](cards/pdf/iam.pdf) |
| 2 |

| AWS STS | 身份 | 9.5 | [MD](cards/markdown/sts.md) | [HTML](cards/html/sts.html) | [PDF](cards/pdf/sts.pdf) |
| 3 |

| AWS Organizations | 多账户 | 9.5 | [MD](cards/markdown/organizations.md) | [HTML](cards/html/organizations.html) | [PDF](cards/pdf/organizations.pdf) |
| 4 |

| AWS Secrets Manager | 机密 | 9.5 | [MD](cards/markdown/secretsmanager.md) | [HTML](cards/html/secretsmanager.html) | [PDF](cards/pdf/secretsmanager.pdf) |
| 5 |

| AWS IAM Identity Center | 身份 | 9.5 | [MD](cards/markdown/identitycenter.md) | [HTML](cards/html/identitycenter.html) | [PDF](cards/pdf/identitycenter.pdf) |
| 6 |

| AWS Redshift | 数据仓库 | 9.2 | [MD](cards/markdown/redshift.md) | [HTML](cards/html/redshift.html) | [PDF](cards/pdf/redshift.pdf) |
| 7 |

| AWS EC2 | 计算 | 9.0 | [MD](cards/markdown/ec2.md) | [HTML](cards/html/ec2.html) | [PDF](cards/pdf/ec2.pdf) |
| 8 |

| AWS S3 | 存储 | 9.0 | [MD](cards/markdown/s3.md) | [HTML](cards/html/s3.html) | [PDF](cards/pdf/s3.pdf) |
| 9 |

| AWS EKS | Kubernetes | 9.0 | [MD](cards/markdown/eks.md) | [HTML](cards/html/eks.html) | [PDF](cards/pdf/eks.pdf) |
| 10 |

| AWS RDS | 数据库 | 9.0 | [MD](cards/markdown/rds.md) | [HTML](cards/html/rds.html) | [PDF](cards/pdf/rds.pdf) |
| 11 |

| AWS CodeBuild & CodePipeline | CI/CD | 9.0 | [MD](cards/markdown/codebuild.md) | [HTML](cards/html/codebuild.html) | [PDF](cards/pdf/codebuild.pdf) |
| 12 |

| AWS Directory Service | 身份 | 9.0 | [MD](cards/markdown/directoryservice.md) | [HTML](cards/html/directoryservice.html) | [PDF](cards/pdf/directoryservice.pdf) |
| 13 |

| AWS Glue | ETL & 数据目录 | 9.0 | [MD](cards/markdown/glue.md) | [HTML](cards/html/glue.html) | [PDF](cards/pdf/glue.pdf) |
| 14 |

| AWS Route 53 | DNS | 9.0 | [MD](cards/markdown/route53.md) | [HTML](cards/html/route53.html) | [PDF](cards/pdf/route53.pdf) |
| 15 |

| AWS Backup | 灾难恢复 | 9.0 | [MD](cards/markdown/backup.md) | [HTML](cards/html/backup.html) | [PDF](cards/pdf/backup.pdf) |
| 16 |

| AWS CloudFormation | 基础设施即代码 | 9.0 | [MD](cards/markdown/cloudformation.md) | [HTML](cards/html/cloudformation.html) | [PDF](cards/pdf/cloudformation.pdf) |
| 17 |

| AWS CloudTrail | 审计日志 | 8.5 | [MD](cards/markdown/cloudtrail.md) | [HTML](cards/html/cloudtrail.html) | [PDF](cards/pdf/cloudtrail.pdf) |
| 18 |

| AWS API Gateway | API | 8.5 | [MD](cards/markdown/apigateway.md) | [HTML](cards/html/apigateway.html) | [PDF](cards/pdf/apigateway.pdf) |
| 19 |

| AWS ECR | 容器 | 8.5 | [MD](cards/markdown/ecr.md) | [HTML](cards/html/ecr.html) | [PDF](cards/pdf/ecr.pdf) |
| 20 |

| AWS ECS | 容器 | 8.5 | [MD](cards/markdown/ecs.md) | [HTML](cards/html/ecs.html) | [PDF](cards/pdf/ecs.pdf) |
| 21 |

| AWS OpenSearch | 搜索 & 分析 | 8.5 | [MD](cards/markdown/opensearch.md) | [HTML](cards/html/opensearch.html) | [PDF](cards/pdf/opensearch.pdf) |
| 22 |

| AWS Systems Manager | 管理 | 8.5 | [MD](cards/markdown/ssm.md) | [HTML](cards/html/ssm.html) | [PDF](cards/pdf/ssm.pdf) |
| 23 |

| AWS SageMaker | 机器学习平台 | 8.5 | [MD](cards/markdown/sagemaker.md) | [HTML](cards/html/sagemaker.html) | [PDF](cards/pdf/sagemaker.pdf) |
| 24 |

| AWS Step Functions | 工作流编排 | 8.5 | [MD](cards/markdown/stepfunctions.md) | [HTML](cards/html/stepfunctions.html) | [PDF](cards/pdf/stepfunctions.pdf) |
| 25 |

| AWS Security Hub | 安全态势 | 8.5 | [MD](cards/markdown/securityhub.md) | [HTML](cards/html/securityhub.html) | [PDF](cards/pdf/securityhub.pdf) |
| 26 |

| AWS Transit Gateway | 网络传输 | 8.5 | [MD](cards/markdown/transitgateway.md) | [HTML](cards/html/transitgateway.html) | [PDF](cards/pdf/transitgateway.pdf) |
| 27 |

| AWS DynamoDB | 数据库 | 8.0 | [MD](cards/markdown/dynamodb.md) | [HTML](cards/html/dynamodb.html) | [PDF](cards/pdf/dynamodb.pdf) |
| 28 |

| AWS Cognito | 身份 | 8.0 | [MD](cards/markdown/cognito.md) | [HTML](cards/html/cognito.html) | [PDF](cards/pdf/cognito.pdf) |
| 29 |

| AWS KMS | 加密 | 8.0 | [MD](cards/markdown/kms.md) | [HTML](cards/html/kms.html) | [PDF](cards/pdf/kms.pdf) |
| 30 |

| AWS EBS | 存储 | 8.0 | [MD](cards/markdown/ebs.md) | [HTML](cards/html/ebs.html) | [PDF](cards/pdf/ebs.pdf) |
| 31 |

| AWS AppSync | 管理的 GraphQL | 8.0 | [MD](cards/markdown/appsync.md) | [HTML](cards/html/appsync.html) | [PDF](cards/pdf/appsync.pdf) |
| 32 |

| AWS Athena | SQL 查询服务 | 8.0 | [MD](cards/markdown/athena.md) | [HTML](cards/html/athena.html) | [PDF](cards/pdf/athena.pdf) |
| 33 |

| AWS DataSync | 数据传输 | 8.0 | [MD](cards/markdown/datasync.md) | [HTML](cards/html/datasync.html) | [PDF](cards/pdf/datasync.pdf) |
| 34 |

| AWS ElastiCache | 内存缓存 | 8.0 | [MD](cards/markdown/elasticache.md) | [HTML](cards/html/elasticache.html) | [PDF](cards/pdf/elasticache.pdf) |
| 35 |

| AWS EventBridge | 事件总线 | 8.0 | [MD](cards/markdown/eventbridge.md) | [HTML](cards/html/eventbridge.html) | [PDF](cards/pdf/eventbridge.pdf) |
| 36 |

| AWS RAM | 多账户 | 8.0 | [MD](cards/markdown/ram.md) | [HTML](cards/html/ram.html) | [PDF](cards/pdf/ram.pdf) |
| 37 |

| AWS MSK | 流式处理 | 7.8 | [MD](cards/markdown/msk.md) | [HTML](cards/html/msk.html) | [PDF](cards/pdf/msk.pdf) |
| 38 |

| AWS Lake Formation | 数据湖 | 7.8 | [MD](cards/markdown/lakeformation.md) | [HTML](cards/html/lakeformation.html) | [PDF](cards/pdf/lakeformation.pdf) |
| 39 |

| AWS Batch | 计算 | 7.5 | [MD](cards/markdown/batch.md) | [HTML](cards/html/batch.html) | [PDF](cards/pdf/batch.pdf) |
| 40 |

| AWS Bedrock | AI/ML | 7.5 | [MD](cards/markdown/bedrock.md) | [HTML](cards/html/bedrock.html) | [PDF](cards/pdf/bedrock.pdf) |
| 41 |

| AWS CloudFront | CDN | 7.5 | [MD](cards/markdown/cloudfront.md) | [HTML](cards/html/cloudfront.html) | [PDF](cards/pdf/cloudfront.pdf) |
| 42 |

| AWS CloudWatch | 监控 | 7.5 | [MD](cards/markdown/cloudwatch.md) | [HTML](cards/html/cloudwatch.html) | [PDF](cards/pdf/cloudwatch.pdf) |
| 43 |

| AWS Config | 合规 & 配置 | 7.5 | [MDcards/markdown/config.md) | [HTML](cards/html/config.html) | [PDF](cards/pdf/config.pdf) |
| 44 |

| AWS EFS | 文件存储 | 7.5 | [MD](cards/markdown/efs.md) | [HTML](cards/html/efs.html) | [PDF](cards/pdf/efs.pdf) |
| 45 |

| AWS Kinesis | 流式处理 | 7.5 | [MD](cards/markdown/kinesis.md) | [HTML](cards/html/kinesis.html) | [PDF](cards/pdf/kinesis.pdf) |
| 46 |

| AWS Lambda | 无服务器 | 7.5 | [MD](cards/markdown/lambda.md) | [HTML](cards/html/lambda.html) | [PDF](cards/pdf/lambda.pdf) |
| 47 |

| AWS MemoryDB | Redis | 7.5 | [MD](cards/markdown/memorydb.md) | [HTML](cards/html/memorydb.html) | [PDF](cards/pdf/memorydb.pdf) |
| 48 |

| AWS Transfer Family | 管理文件传输 | 7.5 | [MD](cards/markdown/transferfamily.md) | [HTML](cards/html/transferfamily.html) | [PDF](cards/pdf/transferfamily.pdf) |
| 49 |

| Amazon Macie | 数据安全 | 7.5 | [MD](cards/markdown/macie.md) | [HTML](cards/html/macie.html) | [PDF](cards/pdf/macie.pdf) |
| 50 |

| AWS VPC | 网络 | 7.0 | [MD](cards/markdown/vpc.md) | [HTML](cards/html/vpc.html) | [PDF](cards/pdf/vpc.pdf) |
| 51 |

| AWS GuardDuty | 威胁检测 | 7.0 | [MD](cards/markdown/guardduty.md) | [HTML](cards/html/guardduty.html) | [PDF](cards/pdf/guardduty.pdf) |
| 52 |

| AWS App Runner | 容器 | 6.5 | [MD](cards/markdown/apprunner.md) | [HTML](cards/html/apprunner.html) | [PDF](cards/pdf/apprunner.pdf) |
| 53 |

| AWS SQS | 队列 | 6.5 | [MD](cards/markdown/sqs.md) | [HTML](cards/html/sqs.html) | [PDF](cards/pdf/sqs.pdf) |
| 54 |

| AWS ELB/ALB | 网络 | 6.0 | [MD](cards/markdown/elb.md) | [HTML](cards/html/elb.html) | [PDF](cards/pdf/elb.pdf) |
| 55 |
 {
var base = (document.querySelector('base') && document.querySelector('base').getAttribute('href')) || '';
var path = base.replace(/\/?$/, '') + '/cap-wasm/cap_wasm.min.js';
window.CAP_CUSTOM_WASM_URL = new URL(path, window.location.href).href;
})();
</script>
</body>
</html>
)