Revisiting Lambda Persistence

LambdaGuard: AWS Lambda auditing tool * Penetration Testing

https://github.com/StateFarmIns/LambdaLooter

Lambda Looter will take a list of profiles and scan through them and download the code you have access to and then process that code for secrets outputting any potential secrets to a loot directory. Even though there can be a lot of false positives it makes looking for loot much faster than scanning the code itself.

CloudGoat goes Serverless: A walkthrough of Vulnerable Lambda Functions - Rhino Security Labs

Ultimate guide to secrets in Lambda