Cloud Security Resources

Comprehensive collection of 184 cloud security resources. Filter by category or search for specific tools, labs, and training materials.

🎯 CTF Challenges & Vulnerable Environments

Preview

OWASP EKS Goat

Intentionally vulnerable AWS EKS environment with 20+ attack-defense labs simulating real-world misconfigurations, IAM flaws, and pod breakout paths.

CTF Labs & Training AWS Kubernetes
Preview

Kubernetes Goat

Interactive Kubernetes security learning platform with guided workbook for GKE, EKS, AKS, or K3S. Deploy in your own cloud account.

CTF Labs & Training Kubernetes Multi-Cloud
Preview

Kubecon NA 2019 CTF

GCP-based CTF with guided workbook covering two attack and defense scenarios plus bonus challenges.

CTF GCP Kubernetes
Preview

OWASP Wrong Secrets

Hands-on vulnerable application teaching secrets management anti-patterns and best practices.

CTF Labs & Training Secrets Management
Preview

CloudGoat

Deliberately vulnerable AWS deployment tool for learning cloud penetration testing. Create scenarios in your own AWS account.

CTF AWS Labs & Training
Preview

FLAWS

Challenge-based website teaching AWS security concepts through real vulnerabilities and misconfigurations.

CTF AWS
Preview

FLAWS 2

Sequel to FLAWS with new AWS security challenges focusing on different attack vectors.

CTF AWS
Preview

Wiz EKS Cluster Games

Vulnerable EKS pod with flag challenges across environment, includes leaderboard and requires registration.

CTF AWS Kubernetes
Preview

Wiz Big IAM Challenge

CTF focused on AWS IAM privilege escalation and permission boundaries.

CTF AWS IAM
Preview

Wiz K8s LAN Party

Network of misconfigurations and vulnerabilities in Kubernetes cluster with leaderboard.

CTF Kubernetes
Preview

Wiz CTF Portal

Central hub for all Wiz CTF challenges and competition. Explore various cloud security challenges with leaderboards and prizes.

CTF Cloud Security Competition
Preview

Thunder CTF

GCP-focused CTF challenges covering various cloud security scenarios.

CTF GCP
Preview

IAM Vulnerable

AWS IAM privilege escalation playground with 31 different attack paths. Deploy with Terraform.

CTF AWS IAM
Preview

CloudFoxable

Deploy vulnerable AWS scenarios using Terraform. Companion to CloudFox enumeration tool.

CTF AWS Labs & Training
Preview

BadZure

Deliberately vulnerable Azure infrastructure for testing and learning.

CTF Azure
Preview

AIGoat

Deliberately vulnerable AI infrastructure from Orca Research for learning AI security.

CTF AI/ML
Preview

CNAPPGoat

Multi-cloud vulnerable environment for testing CNAPP capabilities.

CTF Multi-Cloud
Preview

CICDont

Deliberately vulnerable CI/CD environment for learning pipeline security.

CTF CI/CD
Preview

Bust a Kube

Vulnerable K8S cluster VMs for local VMWare environment.

CTF Kubernetes
Preview

Kube Security Lab

Local Kubernetes security testing environment with 14 vulnerable clusters using Docker, Ansible, and Kind.

CTF Kubernetes Labs & Training
Preview

Blue Team Labs

Defensive security scenarios and detection engineering challenges.

Labs & Training Blue Team

🧪 Hands-On Labs & Training Platforms

Preview

Hack The Box BlackSky

Cloud security specialist labs for AWS, Azure, and GCP with realistic enterprise infrastructure. Earn Cloud Security Specialist certifications.

Labs & Training Certification Multi-Cloud
Preview

Cybr Free AWS Labs

Free 1-click deploy hands-on AWS security labs for building practical skills risk-free.

Labs & Training AWS Free
Preview

Digital Cloud Training Challenge Labs

1000+ scenario-based labs for AWS and Azure with automatic validation, scoring, and multiple difficulty levels.

Labs & Training AWS Azure
Preview

AWS Well-Architected Security Labs

Hands-on labs and documentation for building secure workloads using AWS Well-Architected Framework.

Labs & Training AWS
Preview

Awesome CloudSec Labs

Curated collection of free cloud native security learning labs including CTF, workshops, and research labs.

Labs & Training Multi-Cloud
Preview

Immersive Labs

Cyber drills, labs, and reporting mapped to MITRE ATT&CK, NICE, and NIST frameworks for measuring team readiness.

Labs & Training Platform
Preview

SecureFlag GCP Labs

Hands-on GCP security training covering IAM, network security, encryption, and API security.

Labs & Training GCP
Preview

Pwned Labs

Premium Azure and AWS security labs with assume-breach scenarios and professional certifications.

Labs & Training AWS Azure
Preview

TryHackMe

Gamified cybersecurity training with cloud security learning paths and 800+ labs.

Labs & Training Multi-Cloud
Preview

A Cloud Guru

Comprehensive cloud training platform with AWS, Azure, and GCP security courses.

Training Multi-Cloud
Preview

CBT Nuggets

IT training platform with cloud security certification prep courses.

Training Certification
Preview

Udemy Courses

Wide selection of cloud security courses from various instructors.

Training Multi-Cloud
Preview

Amazon EKS Workshop

Hands-on workshop for learning Amazon EKS including security best practices.

Labs & Training AWS Kubernetes

🛡️ Security Tools & Platforms

Preview

AccuKnox CNAPP

Zero Trust CNAPP with integrated CSPM, CWPP, KSPM, ASPM. Features runtime protection via KubeArmor with eBPF/LSM and inline mitigation.

CNAPP Open Source
Preview

Wiz CNAPP

Agentless CNAPP with security graph technology for visualizing attack paths across AWS, Azure, GCP, OCI, and Alibaba Cloud.

CNAPP Multi-Cloud
Preview

Sysdig Secure

CNAPP leveraging open-source Sysdig and Falco for deep runtime threat detection with eBPF monitoring.

CNAPP Open Source
Preview

Orca Security

Agentless CNAPP with side-scanning technology and attack path analysis showing real-world exploitation scenarios.

CNAPP Agentless
Preview

Aikido Security

Unified code-to-cloud platform combining CSPM, CWPP, SAST, SCA. Traces issues from runtime back to IaC source code.

CNAPP DevSecOps
Preview

Fidelis Security Halo

CNAPP with patented 2MB microagent technology for Windows/Linux with self-installing capabilities.

CNAPP
Preview

Shodan

Search engine for Internet-connected devices. Essential for cloud asset discovery and reconnaissance.

Recon Threat Intel
Preview

ZoomEye

Cyberspace search engine for discovering exposed services and devices.

Recon Threat Intel
Preview

Binary Edge

Internet scanning and attack surface management platform.

Recon Attack Surface
Preview

LeakIX

Search engine for exposed data and misconfigurations.

Recon Data Leaks
Preview

DNSDumpster

DNS reconnaissance and research tool for discovering domain assets.

Recon DNS
Preview

Security Trails

DNS and domain intelligence for attack surface discovery.

Recon DNS
Preview

grep.app

Search across 500K+ GitHub repositories for code, credentials, and configurations.

Code Search Secrets
Preview

Dorksearch

Google dork search tool for finding exposed information.

Recon OSINT
Preview

Packet Storm

Information security news, files, and exploits database.

Research Exploits
Preview

Exploit-DB

Archive of public exploits and vulnerable software.

Research Exploits
Preview

CloudVulnDB

Open-source database of cloud security vulnerabilities.

Research Vulnerabilities
Preview

OWASP

Open Web Application Security Project with cloud security resources.

Framework Research
Preview

Cloud Katana

Cloud adversary emulation tool for testing detection capabilities.

Red Team AWS
Preview

ScoutSuite

Multi-cloud security auditing tool for AWS, Azure, GCP, and more.

CSPM Multi-Cloud Open Source
Preview

Saner CNAPP

Revolutionary CNAPP integrating CSPM, CIEM, CWPP with AI-driven monitoring and automated remediation.

tool CNAPP AI
Preview

AccuKnox CNAPP

Zero Trust CNAPP built on KubeArmor with eBPF runtime protection and inline mitigation.

tool Zero Trust Kubernetes
Preview

Datadog Cloud Security

Real-time threat detection with compliance automation for DevSecOps workflows.

tool Monitoring DevSecOps
Preview

Lacework Polygraph

AI-powered CNAPP with ML anomaly detection and automated threat response.

tool AI CNAPP
Preview

SentinelOne Cloud

AI-powered threat detection for cloud workloads with runtime protection.

tool AI CWPP
Preview

Check Point CloudGuard

Unified security across applications, networks, and workloads with AI-driven threat prevention.

tool CNAPP Enterprise
Preview

Sysdig Secure

Container and Kubernetes-focused security with runtime protection and deep investigation.

tool Kubernetes Container
Preview

CrowdStrike Falcon Cloud

Identity-centric cloud security with continuous monitoring and least-privilege enforcement.

tool Identity CIEM
Preview

Orca Security

Agentless cloud security with SideScanning technology for comprehensive visibility.

tool Agentless CNAPP
Preview

Palo Alto Prisma Cloud

Comprehensive CNAPP with end-to-end security from code to cloud.

tool CNAPP Enterprise

🎓 Certifications & Professional Development

Preview

CCSP Certification

Certified Cloud Security Professional from ISC². Advanced certification requiring 5+ years IT experience covering cloud architecture and risk management.

Certification Advanced
Preview

CKS Certification

Certified Kubernetes Security Specialist from CNCF. Hands-on certification proving command-line proficiency in securing production K8s workloads.

Certification Kubernetes Labs & Training
Preview

Pwned Labs Professional Bootcamps

Cloud attack & defense bootcamps for AWS (ACRTP), Azure/M365 (MCRTP), and GCP (GCRTP) with professional certifications.

Certification Labs & Training Multi-Cloud
Preview

CSA DevSecOps Training

Self-paced course on DevSecOps implementation, challenges, enablers, and culture measurement.

Training DevSecOps
Preview

CSA Cloud Threat Modeling

Training on top 11 cloud threats, threat modeling techniques, and risk treatment methods.

Training Threat Modeling
Preview

AWS Certified Cloud Practitioner

Foundational AWS certification covering cloud concepts and basic security.

Certification AWS Beginner
Preview

AWS Solutions Architect Associate (SAA-C03)

Associate-level AWS certification with security design principles.

Certification AWS
Preview

AWS Solutions Architect Professional

Professional-level AWS certification including advanced security architectures.

Certification AWS Advanced
Preview

Security Certification Roadmap

Comprehensive visual guide to cybersecurity certifications and career paths.

Career Path Guide
Preview

ISC2 CCSP 2025

Updated Certified Cloud Security Professional with new domains: zero trust, DevSecOps, cloud-native security.

certification ISC2 Advanced
Preview

CKS: Kubernetes Security

Certified Kubernetes Security Specialist with hands-on labs for cluster and system hardening.

certification Kubernetes Hands-on
Preview

CSA CCSK v5

Updated Certificate of Cloud Security Knowledge v5 covering latest cloud security domains.

certification CSA CCSK
Preview

GIAC GCSA & GCLD

Cloud Security Automation (GCSA) and Cloud Data (GCLD) focusing on automation and data security.

certification GIAC Automation
Preview

CompTIA Cloud+ 2025

Updated Cloud+ covering cloud security implementation across hybrid environments.

certification CompTIA Entry-Level

🤖 AI Security & LLM Protection

Preview

Tumeryk

Cloud security testing and attack simulation platform. Test cloud infrastructure for security vulnerabilities through automated attacks and provide AI-powered recommendations.

Cloud Testing Vulnerability Testing
Preview

Lakera Guard

Real-time LLM security platform detecting prompt injection, jailbreak attempts, and unsafe behavior with <50ms latency. Industry-leading protection backed by millions of attack data points.

tool AI Security Real-time
Preview

NVIDIA Garak

Open-source LLM vulnerability scanner probing for hallucination, data leakage, prompt injection, toxicity, and jailbreaks. The nmap of AI security.

tool Open Source Scanner
Preview

LLM Guard

Open-source security toolkit with advanced input/output scanners for data leakage prevention, prompt injection detection, and content moderation. 2.5M+ downloads.

tool Open Source Popular
Preview

Rebuff AI

Multi-layered prompt injection detection using heuristics, LLM-based detection, and canary tokens to identify and mitigate vulnerabilities.

tool Prompt Injection Detection
Preview

CalypsoAI Moderator

Model-agnostic enterprise LLM security solution providing real-time scanning, alerts, and comprehensive risk identification at scale.

tool Enterprise Real-time
Preview

NeMo Guardrails

NVIDIA's Python toolkit for adding programmable guardrails to LLM conversational applications, ensuring responsible and ethical AI use.

tool NVIDIA Guardrails
Preview

Guardrails AI

Python package for specifying structure, type validation, and correcting LLM outputs with pre-built measures for various risks.

tool Python Validation
Preview

Giskard AI Security

Automated LLM security testing with heuristics-based and LLM-assisted detectors for domain-specific vulnerabilities in AI applications.

tool Automated Testing
Preview

LLMFuzzer

Open-source fuzzing framework for LLMs focusing on API integrations with diverse fuzzing strategies to identify vulnerabilities.

tool Fuzzing API
Preview

Pynt LLM Security

Dynamic analysis and traffic inspection for LLM APIs, identifying prompt injection pathways and insecure output handling.

tool API Security Dynamic
Preview

BurpGPT

Burp Suite extension integrating LLMs for AI-enhanced web security testing with vulnerability scanning and traffic analysis.

tool Burp Suite Testing
Preview

Lasso Security

End-to-end LLM security solution protecting against external threats and internal vulnerabilities with comprehensive threat modeling.

tool Enterprise Comprehensive
Preview

WhyLabs LLM Security

Multi-layered approach to LLM security with data loss prevention, prompt injection monitoring, and misinformation detection.

tool DLP Monitoring
Preview

Protecto AI

High-precision LLM security evaluation with Privacy Vault for data encryption, anonymization, and secure model deployment.

tool Privacy Encryption
Preview

Vigil

Alpha-stage prompt-level security scanner for high-volume environments requiring prompt validation without infrastructure overhaul.

tool Alpha High-Volume
Preview

OpenAI Aardvark

Agentic security researcher monitoring commits for vulnerabilities using LLM-powered reasoning to identify, explain, and fix security issues.

tool OpenAI Agentic
Preview

Microsoft PyRIT

Python Risk Identification Toolkit for red-teaming LLMs with structured approaches to adversarial testing.

tool Microsoft Red Team
Preview

Constitutional AI

Anthropic's framework for AI safety through constitutional principles, enabling models to self-correct and maintain alignment.

tool Anthropic AI Safety
Preview

Alert AI Gateway

Zero-Trust AI Security Gateway with automatic vulnerability scanning across full development lifecycle.

tool Gateway Zero Trust
Preview

DeepEval

LLM evaluation and guardrails framework with LLM-as-judge for data leakage, prompt injection, jailbreaking, bias, and toxicity detection.

tool Evaluation Open Source
Preview

Nexos.ai Platform

Unified AI governance platform with AI Gateway, AI Workspace, guardrails, and LLM observability for enterprise security.

tool Governance Enterprise
Preview

Granica AI Crunch

AI data platform optimizing training data pipelines with security, privacy, and compliance controls for LLM development.

tool Data Pipeline Privacy
Preview

Mindgard AI

AI security posture management (AI-SPM) for continuous threat monitoring, risk scoring, and automated remediation.

tool AI-SPM Monitoring
Preview

DeepStrike AI Pentesting

AI-specific penetration testing services simulating adversarial attacks, model inversion, and memory poisoning.

tool Pentesting Adversarial
Preview

Hugging Face Model Cards

Standardized model documentation framework for transparency, security evaluation, and risk assessment of AI models.

tool Documentation Standards
Preview

OWASP Top 10 for LLMs 2025

Definitive list of top 10 LLM security vulnerabilities including prompt injection, data poisoning, and excessive agency. Updated for 2025 with new threats.

OWASP Top 10 Essential
Preview

OWASP Agentic AI Top 10 2026

Groundbreaking framework for autonomous AI systems released at Black Hat Europe 2025, covering agentic manipulation and tool poisoning.

OWASP Agentic AI 2026
Preview

Prompt Injection Guide

Comprehensive OWASP guide to prompt injection vulnerabilities, direct and indirect attacks, and mitigation strategies ranked #1 AI security risk.

OWASP Prompt Injection #1 Risk
Preview

CSA Guardrails Guide

Cloud Security Alliance's in-depth guide on building enterprise AI prompt guardrails with DLP integration, multilayered security, and compliance frameworks.

CSA Guardrails Enterprise
Preview

Bypassing LLM Guardrails Research

Academic research demonstrating character injection and AML evasion attacks achieving 100% bypass rates against commercial guardrails.

Research Academic Evasion
Preview

CNAPPs Surge Report

IDC research on CNAPPs as top-3 security investment priority with AI integration reducing alert fatigue and enabling 50% faster response.

IDC CNAPP AI-Driven
Preview

LLM Security Guide

Comprehensive GitHub reference for securing LLMs covering OWASP Top 10, prompt injection, adversarial attacks, and mitigation strategies.

GitHub Comprehensive Guide
Preview

Datadog Guardrails Best Practices

Technical guide on implementing guardrails for LLM security covering input validation, prompt construction, and output filtering.

Best Practices Technical Datadog
Preview

Lakera Prompt Injection Guide

Tactical guide to understanding, recognizing, and preventing prompt injection attacks with real-world examples and defense strategies.

Prompt Injection Tactical Defense
Preview

Obsidian: Prompt Injection #1

Analysis of prompt injection as #1 AI exploit in 2025 appearing in 73% of production deployments with enterprise mitigation strategies.

Enterprise Statistics #1 Exploit
Preview

Confident AI: Ultimate Guardrails Guide

Complete guide to LLM guardrails using LLM-as-judge for data leakage, prompt injection, jailbreaking, and bias detection.

Guide Implementation Technical
Preview

Invicti: OWASP LLM Analysis

Business impact analysis of OWASP Top 10 LLM risks with technical testing methods and defense strategies.

Business Impact Testing OWASP
Preview

Qualys: OWASP 2025 Updates

Analysis of key changes in OWASP Top 10 for LLMs 2025 including RAG vulnerabilities and vector/embedding weaknesses.

OWASP Updates Analysis
Preview

EvidentlyAI: OWASP Testing

Practical guide to testing Gen AI apps against OWASP Top 10 with risk assessment, adversarial testing, and implementation strategies.

Testing Practical OWASP
Preview

Strobes: Mitigation Playbook

Comprehensive mitigation playbook for OWASP Top 10 LLM risks with technical controls and governance frameworks.

Mitigation Playbook Technical
Preview

Nexos.ai: Top 10 LLM Tools

Comparative analysis of top LLM security tools in 2025 based on feature depth, enterprise fit, and industry coverage.

Tools Comparison 2025 Analysis
Preview

Lakera: Top 12 LLM Tools

Curated list of paid and free LLM security tools including vulnerability scanners, guardrails, and testing frameworks.

Tools List Curated Comparison
Preview

Pynt: Essential LLM Tools

Essential LLM security tools covering prompt injection detection, data leakage prevention, and automated security testing.

Tools Guide Essential Implementation
Preview

Protecto: Best LLM Tools 2025

Comprehensive review of best LLM security tools for testing, monitoring, and compliance with implementation guidance.

Review Comprehensive 2025
Preview

Obsidian: AI Pentesting Tools

Specialized AI pentesting tools for uncovering LLM vulnerabilities including prompt injection, model inversion, and memory poisoning.

Pentesting Tools Specialized
Preview

Mindgard: Guardrail Evasion

Research on evading AI guardrails using invisible characters achieving 100% evasion success against major vendors.

Research Evasion Guardrails
Preview

MDPI: Prompt Injection Review

Comprehensive academic review of prompt injection attacks from 2023-2025 analyzing 45 sources with PALADIN defense framework.

Academic Review Comprehensive
Preview

DeepStrike: OWASP Deep Dive

Deep dive into OWASP Top 10 LLM vulnerabilities with real attack scenarios, business impact analysis, and remediation strategies.

OWASP Deep Dive Scenarios
Preview

AccuKnox: Monitoring Tools 2025

Top 7 cloud security monitoring tools in 2025 offering real-time threat detection, runtime protection, and compliance automation.

Monitoring Tools 2025
Preview

TechTarget: CNAPP vs CSPM

Technical comparison of CNAPP and CSPM tools explaining when to use each, with decision frameworks for cloud maturity stages.

Comparison CNAPP CSPM