AbstractClass / CloudPrivs
Determine privileges from cloud credentials via brute-force testing.
☆66Updated 5 months ago
Alternatives and similar repositories for CloudPrivs:
Users that are interested in CloudPrivs are comparing it to the libraries listed below
- ☆58Updated last year
- ☆42Updated 8 months ago
- Enumerate AWS permissions and resources.☆67Updated 2 years ago
- EC2StepShell is an AWS post-exploitation tool for getting high privileges reverse shells in public or private EC2 instances.☆62Updated 5 months ago
- Blogpost series showcasing interesting cloud - web app security bugs☆47Updated last year
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated last year
- A steampipe plugin to query projectdiscovery.io tools.☆26Updated 6 months ago
- ☆55Updated last year
- 🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends☆71Updated last year
- ☆20Updated last year
- A tool for quickly evaluating IAM permissions in AWS.☆57Updated last year
- A multi-cloud DNS record scanner that aims to help cybersecurity/IT analysts identify dangling CNAME records in their cloud DNS services …☆49Updated last year
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆40Updated last year
- Qemuno Framework☆24Updated 2 years ago
- Tool to spray AWS Console IAM Logins☆27Updated 2 years ago
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities☆26Updated 7 months ago
- ☆30Updated 3 years ago
- ☆33Updated 2 months ago
- Tools for attacking Azure Function Apps☆68Updated 3 months ago
- GATOR - GCP Attack Toolkit for Offensive Research, a tool designed to aid in research and exploiting Google Cloud Environments☆89Updated 7 months ago
- An Evil OIDC Server☆53Updated 2 years ago
- dauthi is a tool that takes advantage of API functionality across a variety of MDM solutions to perform user enumeration and single-facto…☆35Updated 9 months ago
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆101Updated 3 months ago
- ☆16Updated 2 years ago
- Automation of Active Directory penetration testing tasks on top of BloodHound CE☆34Updated last year
- ☆45Updated last year
- ServiceLens is a Python tool for analyzing services linked to Microsoft 365 domains. It scans DNS records like SPF and DMARC to identify …☆74Updated 3 months ago
- ☆43Updated 2 weeks ago
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆28Updated last month
- Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information☆73Updated 2 years ago