us-east-1

Kinnaird McQuade

Elite
@kmcquade

Chief Security Architect @BeyondTrust. AI Security and Cloud Security.

awesome-azure-security. A curated list of awesome Microsoft Azure Security tools, guides, blogs, and other resources.

476

OWASP-YouTube-2021. Deliberately vulnerable AWS resources for security assessment demos

33

terraform-aws-policy-sentry. Terraform module for Policy Sentry.

26

conftest-terraform-multifolder-policies. Example of how to write OPA rules with conftest in a modular fashion for Terraform 0.12 plans.

12

terraform-deployment-pentesting. Bits of Terraform that you can use to do bad things in CI/CD pipelines that run Terraform

10

aws-security-scripts. Some python scripts I wrote that help with various specialized AWS security things

10

cheatsheets.kmcquade.com. Github sync of my cheatsheets.kmcquade.com subdomain

9

ansible-role-vault-agent. Ansible Role - HashiCorp Vault Agent - AWS IAM Auto-Auth

8

policy_sentry. IAM Least Privilege Policy Generator

6

pypi-name-hog. Recursively hog namespaces on PyPi according to a YAML file, using GitHub actions.

4

prowler. AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100). Official CIS for AWS guide: https://d0.awsstatic.com/whitepapers/compliance/AWS_CIS_Foundations_Benchmark.pdf

4

powertools-autodoc-proposal. My idea for auto-documenting arguments/input models for Lambda Functions using Lambda Powertools and Pydantic models

4

enumerate-iam. Enumerate the permissions associated with AWS credential set

4

opa-standard-helper-functions. Stash for tried and true standard helper functions

4

quiet-riot. AWS Enumeration and Footprinting Tool

3

checkov. Prevent cloud misconfigurations during build-time for Terraform, Cloudformation, Kubernetes, Serverless framework and other infrastructure-as-code-languages with Checkov by Bridgecrew.

3

cloudsplaining. Cloudsplaining is an AWS IAM Assessment tool that identifies violations of least privilege and generates a risk-prioritized HTML report with a triage worksheet.

3

cloudtracker. CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies.

3

terraform-azurerm-tfstate-backend. Terraform module that provisions an Azure Storage account to store the `terraform.tfstate` file and a Key Vault to store the customer-managed encryption key

3

get-account-authorization-details. Simple boto3 script that runs `aws iam get-authorization-details` with preconfigured options and stores the results in profilename.json

3

terraform-azure-p2s-vpn. Terraform module that creates an Azure Virtual Network, a Gateway Subnet, and a Virtual Gateway (via azurerm_template_deployment).

3

terraform-aws-cartography-demo. Demo Infrastructure for Lyft's Cartography tool

3

ChatGPT. 🤖 ChatGPT Desktop Application (Mac, Windows and Linux)

2

washington_football. Garbage repository for testing Python CI/CD tasks, named after my garbage football team

2

kmcquade. Personal README.md

2

aws-security-odyssey. AWS Security Odyssey: A hands-on journey with security services and controls in the AWS cloud.

2

trailblazer-aws. Blazing CloudTrail since 2018

2

awesome-aws-security. Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security

2

Cloud-Security-Research. Cloud-related research releases from the Rhino Security Labs team.

2

aws-allowlister. Python

2

sleepnumber-github-actions. Use GitHub actions and my Sleep Number bed to wake me up in the morning

2

aws-key-disabler-1. A small lambda script that will disable access keys older than a given amount of days.

2

my-arsenal-of-aws-security-tools. List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

2

kubernetes-security-best-practice. Kubernetes Security - Best Practice Guide

2

aws-credential-compromise-detection. Example detection of compromise credentials in AWS

2

aws-workbox. A Vagrant box packed with some of my favorite AWS tools. Using for training others. Work in progress.

2

aardvark. Aardvark is a multi-account AWS IAM Access Advisor API

2

lambda_checker. Lambda Checker is a simple Python script, based on official AWS Boto3 Python SDK, which executes some security checks to detect misconfigurations issues on Lambda functions. The tool has been developed in order to be automated within CI/CD pipelines or to be executed on demand. In addition to security configuration checks, if the function is written in Python it performs additional security checks such as hardcoded credentials checks, use of assertion clauses and so on.

2

python-security-tool-boilerplate. Boilerplate code for Python based security assessment tools that generate single file HTML reports.

2

azucar. Security auditing tool for Azure environments

2

dummy. Dummy repository

2

Cloud-Pentesting.

2

opa-terraform-exceptions-example. Demo of YAML-based exceptions for OPA policies on Terraform plans.

2

FastAPI_AWS_Cognito. Helper class for user authentication on a FastAPI app with AWS Cognito

1

building-secure-aws-amis-blog-series. This is the code that accompanies my blog post, "Building Secure AWS AMIs."

1

docker-cartography. Dockerizing Lyft's cartography. Publishing this repository to get support from the OGs

1

rick. Rick roll visitors with a GitHub pages site redirect

1

policy_sentry_readthedocs_test. Just trying out ReadTheDocs

1

secretsmanager-demo. Terraform code for the first demo in my October 2018 Webinar on cloud security

1

private-tls-cert. Terraform repo to create self signed certificates for use in HashiCorp Vault Deployment. Separating the ones provided by HashiCorp

1
50
Apply