- 目录
- 1. 序章
- 2. 计算机网络与协议
- 3. 信息收集
- 4. 常见漏洞攻防
- 5. 语言与框架
- 6. 内网渗透
- 7. 云安全
- 8. 防御技术
- 9. 认证机制
- 10. 工具与资源
- 11. 手册速查
- 12. 其他
文章来源于网络收集而来,版权归原创者所有,如有侵权请及时联系!
10.10. 云安全
10.10. 云安全
10.10.1. 云环境自动测试
10.10.1.1. k8s
- checkov Prevent cloud misconfigurations during build-time for Terraform, Cloudformation, Kubernetes, Serverless framework and other infrastructure-as-code-languages with Checkov by Bridgecrew
- CDK Zero Dependency Container Penetration Toolkit
- kube bench
- kube hunter Hunt for security weaknesses in Kubernetes clusters
- KubiScan A tool to scan Kubernetes cluster for risky permissions
- kubescape kubescape is the first tool for testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by to NSA and CISA
- kubeaudit kubeaudit helps you audit your Kubernetes clusters against common security controls
- peirates Kubernetes Penetration Testing tool
- datree Prevent Kubernetes misconfigurations from reaching production
10.10.1.2. 容器
- botb A container analysis and exploitation tool for pentesters and engineers
10.10.2. 安全加固
- falco Cloud Native Runtime Security
10.10.3. 云上扫描
- Cloud Custodian Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
- cloudquery cloudquery transforms your cloud infrastructure into SQL database for easy monitoring, governance and security
10.10.4. 靶场环境
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论