Aura Information Security
Official@aurainfosec · Wellington, New Zealand
Offers specialized technical auditing and configuration validation for AWS cloud environments, focusing on identity, infrastructure, and network security posture.
Agent Skills by Aura Information Security
Showing 29 vetted skills indexed across 1 GitHub repositories.
testssl
Probe TLS/SSL services with testssl.sh and report severity-mapped vulnerabilities.
pmapper
Identify IAM privilege escalation paths to administrative access in AWS accounts.
secrets-manager
Store, retrieve, and rotate application credentials in AWS Secrets Manager.
eventbridge
Configure AWS EventBridge event buses, rules, patterns, and targets.
cloudwatch
Automates CloudWatch alarms, metrics, logs queries, and dashboards via APIs or CLI.
s3
Audit AWS S3 bucket public accessibility and edge-case exposure.
poc-generator
Generate privilege escalation proof-of-concept playbooks from confirmed AWS security findings.
docker
Build Docker images, run containers, and orchestrate multi-service setups with Docker Compose.
sns
Design and validate AWS SNS pub/sub configurations for event-driven messaging.
api-gateway
Automate AWS API Gateway configuration and troubleshooting for REST and HTTP APIs.
cross-account
Run AWS security audits across multiple accounts with credential switching.
cognito
Audits AWS Cognito user pool and identity configurations for security weaknesses.
nmap-scan
Scan specified targets with Nmap for open ports and services.
output
Format AWS security audit query results into two-phase responses with evidence and findings.
prowler
Run Prowler AWS security scans and validate FAIL findings with AWS CLI evidence.
dynamodb
Design DynamoDB schemas, indexes, and query patterns with troubleshooting guidance.
validation-rules
Map AWS security claim IDs to read-only CLI checks and probe procedures.
ecs
Validate AWS ECS container security and internet exposure using API and network checks.
step-functions
Orchestrate AWS workflows by defining state machines with branching, concurrency, and retries.
sqs
Probe AWS SQS queues for unauthenticated public read and write access.
bedrock
Invoke AWS Bedrock foundation models for text generation and embeddings.
identity-blast-radius
Resolve IAM effective permissions and enumerate reachable AWS resources for blast-radius assessment.
curl
Execute HTTP requests for API testing, debugging, and file transfers.
iam
Diagnose AWS IAM access-control weaknesses and validate least-privilege policies.
Frequently Asked Questions About Aura Information Security
FAQPage SchemaWhat specific security tasks can I perform using these capabilities?▼
You can conduct comprehensive AWS security audits, including IAM privilege escalation analysis, S3 bucket exposure checks, TLS/SSL service probing, and EKS cluster security validation. These capabilities enable systematic identification of misconfigurations and security weaknesses across your cloud infrastructure.
Which technical personas benefit most from these security checks?▼
Cloud security engineers, DevSecOps practitioners, and infrastructure auditors benefit from these capabilities. They are designed for professionals responsible for maintaining least-privilege access, hardening cloud environments, and ensuring compliance across complex, multi-account AWS architectures.
What are the prerequisites for running these security audits?▼
Execution requires an AWS environment with appropriate read-only IAM permissions to query resource configurations and metadata. Users must have a configured environment capable of executing standard network requests and interacting with AWS services to perform the validation checks.