69 AWS Services Covered

    AWS Security Cards

    Free, comprehensive security reference guides for every major AWS service. Attack vectors, misconfigurations, CLI commands, and detection indicators.

    By Toc Consulting - AWS Security & Cloud Architecture

    75 cards found

    AWS IAM Security Card
    AWS IAM

    AWS IAM

    Identity & Security

    Identity & Access Management - Users, roles, policies

    View Card
    AWS S3 Security Card
    AWS S3

    AWS S3

    Storage

    Simple Storage Service - Buckets & objects

    View Card
    AWS EC2 Security Card
    AWS EC2

    AWS EC2

    Compute

    Elastic Compute Cloud - Instances & IMDS

    View Card
    AWS Lambda Security Card
    AWS Lambda

    AWS Lambda

    Compute

    Serverless compute - Functions & triggers

    View Card
    AWS KMS Security Card
    AWS KMS

    AWS KMS

    Identity & Security

    Key Management Service - Encryption keys & cryptographic operations

    View Card
    AWS RDS Security Card
    AWS RDS

    AWS RDS

    Database

    Relational Database Service - Databases & snapshots

    View Card
    Secrets Manager Security Card
    Secrets Manager

    Secrets Manager

    Identity & Security

    Secret storage & rotation

    View Card
    AWS VPC Security Card
    AWS VPC

    AWS VPC

    Networking

    Virtual Private Cloud - Network isolation & security groups

    View Card
    AWS ECS Security Card
    AWS ECS

    AWS ECS

    Compute

    Elastic Container Service - Container orchestration

    View Card
    AWS EKS Security Card
    AWS EKS

    AWS EKS

    Compute

    Elastic Kubernetes Service - Managed Kubernetes

    View Card
    AWS ELB/ALB Security Card
    AWS ELB/ALB

    AWS ELB/ALB

    Networking

    Elastic Load Balancing - Traffic distribution

    View Card
    AWS STS Security Card
    AWS STS

    AWS STS

    Identity & Security

    Security Token Service - Temporary credentials & role assumption

    View Card
    AWS EBS Security Card
    AWS EBS

    AWS EBS

    Storage

    Elastic Block Store - Volumes & snapshots

    View Card
    AWS EFS Security Card
    AWS EFS

    AWS EFS

    Storage

    Elastic File System - Managed NFS storage

    View Card
    AWS Cognito Security Card
    AWS Cognito

    AWS Cognito

    Identity & Security

    User pools & identity federation

    View Card
    AWS ACM Security Card
    AWS ACM

    AWS ACM

    Identity & Security

    Certificate Manager - SSL/TLS certificates

    View Card
    AWS CloudFront Security Card
    AWS CloudFront

    AWS CloudFront

    Networking

    Content Delivery Network - Edge caching & distribution

    View Card
    AWS CloudTrail Security Card
    AWS CloudTrail

    AWS CloudTrail

    Monitoring

    API logging & audit trail

    View Card
    AWS GuardDuty Security Card
    AWS GuardDuty

    AWS GuardDuty

    Monitoring

    Threat detection service

    View Card
    AWS Organizations Security Card
    AWS Organizations

    AWS Organizations

    Management

    Multi-account management - SCP configuration

    View Card
    AWS SSM Security Card
    AWS SSM

    AWS SSM

    Management

    Systems Manager - Remote management

    View Card
    AWS SNS Security Card
    AWS SNS

    AWS SNS

    Integration

    Simple Notification Service - Message routing

    View Card
    AWS SQS Security Card
    AWS SQS

    AWS SQS

    Integration

    Simple Queue Service - Message queuing

    View Card
    AWS DynamoDB Security Card
    AWS DynamoDB

    AWS DynamoDB

    Database

    NoSQL database - Tables & streams

    View Card
    API Gateway Security Card
    API Gateway

    API Gateway

    Networking

    REST/WebSocket APIs - Authorization & throttling

    View Card
    AWS Route 53 Security Card
    AWS Route 53

    AWS Route 53

    Networking

    DNS service - Domain management

    View Card
    AWS CloudWatch Security Card
    AWS CloudWatch

    AWS CloudWatch

    Monitoring

    Monitoring & observability - Logs & metrics

    View Card
    AWS EventBridge Security Card
    AWS EventBridge

    AWS EventBridge

    Integration

    Event bus - Event routing & rules

    View Card
    AWS Glue Security Card
    AWS Glue

    AWS Glue

    Analytics

    ETL & Data Catalog - Data transformation

    View Card
    AWS Athena Security Card
    AWS Athena

    AWS Athena

    Analytics

    SQL query service - Data lake queries

    View Card
    AWS Kinesis Security Card
    AWS Kinesis

    AWS Kinesis

    Analytics

    Real-time streaming - Data ingestion

    View Card
    Step Functions Security Card
    Step Functions

    Step Functions

    Integration

    Workflow orchestration - State machines

    View Card
    CodeBuild/Pipeline Security Card
    CodeBuild/Pipeline

    CodeBuild/Pipeline

    Management

    CI/CD services - Build & deploy pipelines

    View Card
    AWS ECR Security Card
    AWS ECR

    AWS ECR

    Compute

    Container registry - Image management

    View Card
    AWS Backup Security Card
    AWS Backup

    AWS Backup

    Storage

    Backup vaults & recovery points

    View Card
    AWS WAF Security Card
    AWS WAF

    AWS WAF

    Networking

    Web Application Firewall - Rule management

    View Card
    AWS ElastiCache Security Card
    AWS ElastiCache

    AWS ElastiCache

    Database

    Redis & Memcached - In-memory caching

    View Card
    AWS OpenSearch Security Card
    AWS OpenSearch

    AWS OpenSearch

    Analytics

    Search & analytics - Dashboards & indices

    View Card
    AWS Redshift Security Card
    AWS Redshift

    AWS Redshift

    Database

    Data warehouse - Business analytics

    View Card
    AWS Inspector Security Card
    AWS Inspector

    AWS Inspector

    Monitoring

    Vulnerability scanning - Automated assessment

    View Card
    AWS Config Security Card
    AWS Config

    AWS Config

    Monitoring

    Configuration compliance - Rule evaluation

    View Card
    AWS Transfer Family Security Card
    AWS Transfer Family

    AWS Transfer Family

    Integration

    SFTP/FTPS service - File transfer

    View Card
    AWS AppSync Security Card
    AWS AppSync

    AWS AppSync

    Networking

    GraphQL APIs - Real-time data sync

    View Card
    AWS Batch Security Card
    AWS Batch

    AWS Batch

    Compute

    Job execution - Batch processing

    View Card
    AWS Directory Service Security Card
    AWS Directory Service

    AWS Directory Service

    Identity & Security

    Managed Active Directory - Domain services

    View Card
    AWS SageMaker Security Card
    AWS SageMaker

    AWS SageMaker

    AI/ML

    Machine learning - Model training & deployment

    View Card
    AWS Bedrock Security Card
    AWS Bedrock

    AWS Bedrock

    AI/ML

    Foundation models - LLM APIs & guardrails

    View Card
    AWS MSK Security Card
    AWS MSK

    AWS MSK

    Analytics

    Managed Kafka - Streaming & topics

    View Card
    AWS App Runner Security Card
    AWS App Runner

    AWS App Runner

    Compute

    Container deployment - Auto-scaling apps

    View Card
    AWS MemoryDB Security Card
    AWS MemoryDB

    AWS MemoryDB

    Database

    Redis compatible - Durable in-memory database

    View Card
    AWS Amplify Security Card
    AWS Amplify

    AWS Amplify

    Compute

    Frontend hosting - Full-stack deployment

    View Card
    AWS DataSync Security Card
    AWS DataSync

    AWS DataSync

    Integration

    Data transfer - Cross-environment sync

    View Card
    AWS Lake Formation Security Card
    AWS Lake Formation

    AWS Lake Formation

    Analytics

    Data lake governance - Fine-grained access

    View Card
    AWS Network Firewall Security Card
    AWS Network Firewall

    AWS Network Firewall

    Networking

    Managed firewall - Suricata rules

    View Card
    AWS CloudFormation Security Card
    AWS CloudFormation

    AWS CloudFormation

    Management

    Infrastructure as Code - Stack provisioning

    View Card
    AWS IAM Identity Center Security Card
    AWS IAM Identity Center

    AWS IAM Identity Center

    Identity & Security

    SSO federation - Multi-account access

    View Card
    AWS Security Hub Security Card
    AWS Security Hub

    AWS Security Hub

    Monitoring

    Security posture - Finding aggregation

    View Card
    AWS Transit Gateway Security Card
    AWS Transit Gateway

    AWS Transit Gateway

    Networking

    Network hub - Cross-VPC routing

    View Card
    AWS RAM Security Card
    AWS RAM

    AWS RAM

    Management

    Resource sharing - Cross-account access

    View Card
    Amazon Macie Security Card
    Amazon Macie

    Amazon Macie

    Monitoring

    Data security - Sensitive data discovery

    View Card
    AWS CloudHSM Security Card
    AWS CloudHSM

    AWS CloudHSM

    Identity & Security

    Hardware Security Module - FIPS 140-3 Level 3 key management

    View Card
    AWS Shield Security Card
    AWS Shield

    AWS Shield

    Networking

    DDoS protection - Standard and Advanced with SRT

    View Card
    Amazon Detective Security Card
    Amazon Detective

    Amazon Detective

    Monitoring

    Security investigation - Behavior graphs from CloudTrail, VPC, GuardDuty

    View Card
    AWS Firewall Manager Security Card
    AWS Firewall Manager

    AWS Firewall Manager

    Management

    Central firewall management - WAF, SG, Network Firewall policies

    View Card
    AWS Verified Access Security Card
    AWS Verified Access

    AWS Verified Access

    Networking

    Zero trust network access - Cedar policies and trust providers

    View Card
    AWS Control Tower Security Card
    AWS Control Tower

    AWS Control Tower

    Management

    Landing zone governance - Guardrails, SCPs, account factory

    View Card
    Amazon EMR Security Card
    Amazon EMR

    Amazon EMR

    Analytics

    Hadoop/Spark clusters - IMDS, web UIs, step injection

    View Card
    AWS Elastic Beanstalk Security Card
    AWS Elastic Beanstalk

    AWS Elastic Beanstalk

    Compute

    Application deployment - Service roles, .ebextensions, env vars

    View Card
    Amazon WorkSpaces Security Card
    Amazon WorkSpaces

    Amazon WorkSpaces

    Compute

    Virtual desktops - AD integration, credential harvesting

    View Card
    Amazon DocumentDB Security Card
    Amazon DocumentDB

    Amazon DocumentDB

    Database

    MongoDB-compatible database - NoSQL injection, snapshots

    View Card
    Amazon Neptune Security Card
    Amazon Neptune

    Amazon Neptune

    Database

    Graph database - Gremlin/SPARQL injection, notebooks

    View Card
    Amazon QuickSight Security Card
    Amazon QuickSight

    Amazon QuickSight

    Analytics

    BI dashboards - Data source exposure, embedded leaks

    View Card
    Amazon Lightsail Security Card
    Amazon Lightsail

    Amazon Lightsail

    Compute

    Simplified compute - Default SSH keys, open firewalls

    View Card
    AWS X-Ray Security Card
    AWS X-Ray

    AWS X-Ray

    Monitoring

    Distributed tracing - Sensitive data in traces, C2 abuse

    View Card
    Amazon Verified Permissions Security Card
    Amazon Verified Permissions

    Amazon Verified Permissions

    Identity & Security

    Cedar authorization - Policy logic flaws, schema bypass

    View Card