TocConsulting/aws-security-cards

GitHub: TocConsulting/aws-security-cards

提供AWS服务安全参考卡片,帮助识别安全风险。

Stars: 4 | Forks: 0

AWS Security Cards

# AWS 安全卡 **75 张 AWS 服务安全参考卡**,涵盖攻击向量、误配置、枚举命令、权限提升、持久化技术、检测指标和防御建议。 每张卡片都提供三种格式: - **Markdown** - 可在 GitHub 上阅读,易于搜索和贡献 - **HTML** - 美观的独立深色主题页面,在任何浏览器中打开 - **PDF** - 打印就绪,与团队分享 开源社区项目。 ## 安全卡 | # | | 服务 | 类别 | 风险 | Markdown | HTML | PDF | |---|--|---------|----------|------|----------|------|-----| | 1 | | AWS IAM | 身份 | 9.5 | [MD](cards/markdown/iam.md) | [HTML](cards/html/iam.html) | [PDF](cards/pdf/iam.pdf) | | 2 | | AWS STS | 身份 | 9.5 | [MD](cards/markdown/sts.md) | [HTML](cards/html/sts.html) | [PDF](cards/pdf/sts.pdf) | | 3 | | AWS Organizations | 多账户 | 9.5 | [MD](cards/markdown/organizations.md) | [HTML](cards/html/organizations.html) | [PDF](cards/pdf/organizations.pdf) | | 4 | | AWS Secrets Manager | 机密 | 9.5 | [MD](cards/markdown/secretsmanager.md) | [HTML](cards/html/secretsmanager.html) | [PDF](cards/pdf/secretsmanager.pdf) | | 5 | | AWS IAM Identity Center | 身份 | 9.5 | [MD](cards/markdown/identitycenter.md) | [HTML](cards/html/identitycenter.html) | [PDF](cards/pdf/identitycenter.pdf) | | 6 | | AWS Redshift | 数据仓库 | 9.2 | [MD](cards/markdown/redshift.md) | [HTML](cards/html/redshift.html) | [PDF](cards/pdf/redshift.pdf) | | 7 | | AWS EC2 | 计算 | 9.0 | [MD](cards/markdown/ec2.md) | [HTML](cards/html/ec2.html) | [PDF](cards/pdf/ec2.pdf) | | 8 | | AWS S3 | 存储 | 9.0 | [MD](cards/markdown/s3.md) | [HTML](cards/html/s3.html) | [PDF](cards/pdf/s3.pdf) | | 9 | | AWS EKS | Kubernetes | 9.0 | [MD](cards/markdown/eks.md) | [HTML](cards/html/eks.html) | [PDF](cards/pdf/eks.pdf) | | 10 | | AWS RDS | 数据库 | 9.0 | [MD](cards/markdown/rds.md) | [HTML](cards/html/rds.html) | [PDF](cards/pdf/rds.pdf) | | 11 | | AWS CodeBuild & CodePipeline | CI/CD | 9.0 | [MD](cards/markdown/codebuild.md) | [HTML](cards/html/codebuild.html) | [PDF](cards/pdf/codebuild.pdf) | | 12 | | AWS Directory Service | 身份 | 9.0 | [MD](cards/markdown/directoryservice.md) | [HTML](cards/html/directoryservice.html) | [PDF](cards/pdf/directoryservice.pdf) | | 13 | | AWS Glue | ETL & 数据目录 | 9.0 | [MD](cards/markdown/glue.md) | [HTML](cards/html/glue.html) | [PDF](cards/pdf/glue.pdf) | | 14 | | AWS Route 53 | DNS | 9.0 | [MD](cards/markdown/route53.md) | [HTML](cards/html/route53.html) | [PDF](cards/pdf/route53.pdf) | | 15 | | AWS Backup | 灾难恢复 | 9.0 | [MD](cards/markdown/backup.md) | [HTML](cards/html/backup.html) | [PDF](cards/pdf/backup.pdf) | | 16 | | AWS CloudFormation | 基础设施即代码 | 9.0 | [MD](cards/markdown/cloudformation.md) | [HTML](cards/html/cloudformation.html) | [PDF](cards/pdf/cloudformation.pdf) | | 17 | | AWS CloudTrail | 审计日志 | 8.5 | [MD](cards/markdown/cloudtrail.md) | [HTML](cards/html/cloudtrail.html) | [PDF](cards/pdf/cloudtrail.pdf) | | 18 | | AWS API Gateway | API | 8.5 | [MD](cards/markdown/apigateway.md) | [HTML](cards/html/apigateway.html) | [PDF](cards/pdf/apigateway.pdf) | | 19 | | AWS ECR | 容器 | 8.5 | [MD](cards/markdown/ecr.md) | [HTML](cards/html/ecr.html) | [PDF](cards/pdf/ecr.pdf) | | 20 | | AWS ECS | 容器 | 8.5 | [MD](cards/markdown/ecs.md) | [HTML](cards/html/ecs.html) | [PDF](cards/pdf/ecs.pdf) | | 21 | | AWS OpenSearch | 搜索 & 分析 | 8.5 | [MD](cards/markdown/opensearch.md) | [HTML](cards/html/opensearch.html) | [PDF](cards/pdf/opensearch.pdf) | | 22 | | AWS Systems Manager | 管理 | 8.5 | [MD](cards/markdown/ssm.md) | [HTML](cards/html/ssm.html) | [PDF](cards/pdf/ssm.pdf) | | 23 | | AWS SageMaker | 机器学习平台 | 8.5 | [MD](cards/markdown/sagemaker.md) | [HTML](cards/html/sagemaker.html) | [PDF](cards/pdf/sagemaker.pdf) | | 24 | | AWS Step Functions | 工作流编排 | 8.5 | [MD](cards/markdown/stepfunctions.md) | [HTML](cards/html/stepfunctions.html) | [PDF](cards/pdf/stepfunctions.pdf) | | 25 | | AWS Security Hub | 安全态势 | 8.5 | [MD](cards/markdown/securityhub.md) | [HTML](cards/html/securityhub.html) | [PDF](cards/pdf/securityhub.pdf) | | 26 | | AWS Transit Gateway | 网络传输 | 8.5 | [MD](cards/markdown/transitgateway.md) | [HTML](cards/html/transitgateway.html) | [PDF](cards/pdf/transitgateway.pdf) | | 27 | | AWS DynamoDB | 数据库 | 8.0 | [MD](cards/markdown/dynamodb.md) | [HTML](cards/html/dynamodb.html) | [PDF](cards/pdf/dynamodb.pdf) | | 28 | | AWS Cognito | 身份 | 8.0 | [MD](cards/markdown/cognito.md) | [HTML](cards/html/cognito.html) | [PDF](cards/pdf/cognito.pdf) | | 29 | | AWS KMS | 加密 | 8.0 | [MD](cards/markdown/kms.md) | [HTML](cards/html/kms.html) | [PDF](cards/pdf/kms.pdf) | | 30 | | AWS EBS | 存储 | 8.0 | [MD](cards/markdown/ebs.md) | [HTML](cards/html/ebs.html) | [PDF](cards/pdf/ebs.pdf) | | 31 | | AWS AppSync | 管理的 GraphQL | 8.0 | [MD](cards/markdown/appsync.md) | [HTML](cards/html/appsync.html) | [PDF](cards/pdf/appsync.pdf) | | 32 | | AWS Athena | SQL 查询服务 | 8.0 | [MD](cards/markdown/athena.md) | [HTML](cards/html/athena.html) | [PDF](cards/pdf/athena.pdf) | | 33 | | AWS DataSync | 数据传输 | 8.0 | [MD](cards/markdown/datasync.md) | [HTML](cards/html/datasync.html) | [PDF](cards/pdf/datasync.pdf) | | 34 | | AWS ElastiCache | 内存缓存 | 8.0 | [MD](cards/markdown/elasticache.md) | [HTML](cards/html/elasticache.html) | [PDF](cards/pdf/elasticache.pdf) | | 35 | | AWS EventBridge | 事件总线 | 8.0 | [MD](cards/markdown/eventbridge.md) | [HTML](cards/html/eventbridge.html) | [PDF](cards/pdf/eventbridge.pdf) | | 36 | | AWS RAM | 多账户 | 8.0 | [MD](cards/markdown/ram.md) | [HTML](cards/html/ram.html) | [PDF](cards/pdf/ram.pdf) | | 37 | | AWS MSK | 流式处理 | 7.8 | [MD](cards/markdown/msk.md) | [HTML](cards/html/msk.html) | [PDF](cards/pdf/msk.pdf) | | 38 | | AWS Lake Formation | 数据湖 | 7.8 | [MD](cards/markdown/lakeformation.md) | [HTML](cards/html/lakeformation.html) | [PDF](cards/pdf/lakeformation.pdf) | | 39 | | AWS Batch | 计算 | 7.5 | [MD](cards/markdown/batch.md) | [HTML](cards/html/batch.html) | [PDF](cards/pdf/batch.pdf) | | 40 | | AWS Bedrock | AI/ML | 7.5 | [MD](cards/markdown/bedrock.md) | [HTML](cards/html/bedrock.html) | [PDF](cards/pdf/bedrock.pdf) | | 41 | | AWS CloudFront | CDN | 7.5 | [MD](cards/markdown/cloudfront.md) | [HTML](cards/html/cloudfront.html) | [PDF](cards/pdf/cloudfront.pdf) | | 42 | | AWS CloudWatch | 监控 | 7.5 | [MD](cards/markdown/cloudwatch.md) | [HTML](cards/html/cloudwatch.html) | [PDF](cards/pdf/cloudwatch.pdf) | | 43 | | AWS Config | 合规 & 配置 | 7.5 | [MDcards/markdown/config.md) | [HTML](cards/html/config.html) | [PDF](cards/pdf/config.pdf) | | 44 | | AWS EFS | 文件存储 | 7.5 | [MD](cards/markdown/efs.md) | [HTML](cards/html/efs.html) | [PDF](cards/pdf/efs.pdf) | | 45 | | AWS Kinesis | 流式处理 | 7.5 | [MD](cards/markdown/kinesis.md) | [HTML](cards/html/kinesis.html) | [PDF](cards/pdf/kinesis.pdf) | | 46 | | AWS Lambda | 无服务器 | 7.5 | [MD](cards/markdown/lambda.md) | [HTML](cards/html/lambda.html) | [PDF](cards/pdf/lambda.pdf) | | 47 | | AWS MemoryDB | Redis | 7.5 | [MD](cards/markdown/memorydb.md) | [HTML](cards/html/memorydb.html) | [PDF](cards/pdf/memorydb.pdf) | | 48 | | AWS Transfer Family | 管理文件传输 | 7.5 | [MD](cards/markdown/transferfamily.md) | [HTML](cards/html/transferfamily.html) | [PDF](cards/pdf/transferfamily.pdf) | | 49 | | Amazon Macie | 数据安全 | 7.5 | [MD](cards/markdown/macie.md) | [HTML](cards/html/macie.html) | [PDF](cards/pdf/macie.pdf) | | 50 | | AWS VPC | 网络 | 7.0 | [MD](cards/markdown/vpc.md) | [HTML](cards/html/vpc.html) | [PDF](cards/pdf/vpc.pdf) | | 51 | | AWS GuardDuty | 威胁检测 | 7.0 | [MD](cards/markdown/guardduty.md) | [HTML](cards/html/guardduty.html) | [PDF](cards/pdf/guardduty.pdf) | | 52 | | AWS App Runner | 容器 | 6.5 | [MD](cards/markdown/apprunner.md) | [HTML](cards/html/apprunner.html) | [PDF](cards/pdf/apprunner.pdf) | | 53 | | AWS SQS | 队列 | 6.5 | [MD](cards/markdown/sqs.md) | [HTML](cards/html/sqs.html) | [PDF](cards/pdf/sqs.pdf) | | 54 | | AWS ELB/ALB | 网络 | 6.0 | [MD](cards/markdown/elb.md) | [HTML](cards/html/elb.html) | [PDF](cards/pdf/elb.pdf) | | 55 |