Determine privileges from cloud credentials via brute-force testing.
☆69Aug 22, 2024Updated last year
Alternatives and similar repositories for CloudPrivs
Users that are interested in CloudPrivs are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆79Aug 2, 2023Updated 2 years ago
- ☆28Dec 28, 2017Updated 8 years ago
- RedBlock is an Nginx module designed for offensive security operations and red teaming. This module empowers security professionals to ea…☆24Jan 21, 2024Updated 2 years ago
- A Python script to authenticate and test access to Google Cloud Platform (GCP) resources.☆19Jan 31, 2024Updated 2 years ago
- Golang Shlyuz Implant Implementation☆13May 23, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Syscall BOF to arbitrarily add/detract process token privilege rights.☆68Jul 10, 2024Updated 2 years ago
- C# alternative to the linux "cat" command... Prints file contents to console. For use with Cobalt Strike's Execute-Assembly☆15Jul 15, 2021Updated 5 years ago
- treafik fronted c2 examples☆25Dec 6, 2020Updated 5 years ago
- Beacon Object File allowing creation of Beacons in different sessions.☆84May 23, 2022Updated 4 years ago
- This tool implements a cloud version of the Shadow Copy attack against domain controllers running in AWS using only the EC2:CreateSnapsho…☆124Nov 2, 2019Updated 6 years ago
- An Evil OIDC Server☆53Oct 19, 2022Updated 3 years ago
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆59Sep 20, 2023Updated 2 years ago
- A BOF.NET program to split a file into smaller chunks and email it via a specified SMTP relay.☆17Jun 24, 2021Updated 5 years ago
- Beacon Object Files used for Cobalt Strike☆19Jul 18, 2023Updated 3 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Enumerate valid users within Microsoft Teams and OneDrive with clean output.☆62Feb 4, 2025Updated last year
- Script to setup a phishing server on the cloud☆13Apr 30, 2021Updated 5 years ago
- A fast enumeration tool for publicly exposed Azure Storage blobs.☆123Mar 25, 2023Updated 3 years ago
- Authorized cloud adversary simulation and validation toolkit☆107Updated this week
- ☆21Jul 11, 2026Updated last week
- Ansible role to deploy RedELK server☆19Sep 11, 2023Updated 2 years ago
- Cobalt Strike Aggressor Script that Performs System/AV/EDR Recon☆339Jun 6, 2022Updated 4 years ago
- A set of hashcat hcmask files, prioritized by cracking efficiency... and the hcmask_Generator_9000.xlsx tool.☆26Dec 17, 2023Updated 2 years ago
- Extended Process List (Search functionality)☆29Jan 23, 2021Updated 5 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- ☆37May 8, 2022Updated 4 years ago
- Microsoft Graph API post-exploitation toolkit☆95Jul 13, 2024Updated 2 years ago
- A serverless C2 framework☆14Feb 3, 2023Updated 3 years ago
- ☆39Jun 9, 2021Updated 5 years ago
- PoC MSI payload based on ASEC/AhnLab's blog post☆25Sep 19, 2022Updated 3 years ago
- My implementation of the GIUDA project in C++☆191Jul 25, 2023Updated 2 years ago
- cloudgrep is grep for cloud storage☆332Mar 14, 2026Updated 4 months ago
- ☆125May 12, 2021Updated 5 years ago
- Python module for running BOFs☆80Nov 28, 2025Updated 7 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- EC2StepShell is an AWS post-exploitation tool for getting high privileges reverse shells in public or private EC2 instances.☆71Sep 20, 2024Updated last year
- Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique☆160Nov 7, 2023Updated 2 years ago
- Small utility to chunk up a large BloodHound JSON file into smaller files for importing.☆98Apr 13, 2023Updated 3 years ago
- Hide from the InstanceCredentialExfiltration GuardDuty finding by using VPC Endpoints☆121Jul 13, 2025Updated last year
- ☆56Apr 25, 2023Updated 3 years ago
- RCE exploit for CVE-2023-3519☆228Aug 23, 2023Updated 2 years ago
- Utility to analyse, ingest and push out credentials from common data sources during an internal penetration test.☆19Jun 12, 2022Updated 4 years ago