返回介绍

10.10. 云安全

发布于 2024-02-07 20:47:54 字数 2466 浏览 0 评论 0 收藏 0

10.10. 云安全

10.10.1. 云环境自动测试

10.10.1.1. k8s

  • checkov Prevent cloud misconfigurations during build-time for Terraform, Cloudformation, Kubernetes, Serverless framework and other infrastructure-as-code-languages with Checkov by Bridgecrew
  • CDK Zero Dependency Container Penetration Toolkit
  • kube bench
  • kube hunter Hunt for security weaknesses in Kubernetes clusters
  • KubiScan A tool to scan Kubernetes cluster for risky permissions
  • kubescape kubescape is the first tool for testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by to NSA and CISA
  • kubeaudit kubeaudit helps you audit your Kubernetes clusters against common security controls
  • peirates Kubernetes Penetration Testing tool
  • datree Prevent Kubernetes misconfigurations from reaching production

10.10.1.2. 容器

  • botb A container analysis and exploitation tool for pentesters and engineers

10.10.2. 安全加固

  • falco Cloud Native Runtime Security

10.10.3. 云上扫描

  • Cloud Custodian Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
  • cloudquery cloudquery transforms your cloud infrastructure into SQL database for easy monitoring, governance and security

10.10.4. 靶场环境

  • metarget a framework providing automatic constructions of vulnerable infrastructures.
  • CloudGoat Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据
    我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
    原文