AWS Cross-Service Attacks
Understanding and Preventing Cross-Service Confused Deputy Vulnerabilities in AWS
Understanding and Preventing Cross-Service Confused Deputy Vulnerabilities in AWS
Exploiting overly permissive VPC endpoints to exfiltrate data from private AWS subnets
Simple method to define and build security testing containers in Podman
Attacking AWS Accounts from a black box perspective
Using Snotra to Check For Sensitive Tags
AWS and overly permissive GitHub OIDC cross-account role trust policies
Blog post about Cloud Configuration Reviews
Continuous AWS Testing with Snotra, Lambda, Cloud Watch EventBridge and S3.