DavidDikker / endgame
An AWS Pentesting tool that lets you use one-liner commands to backdoor an AWS account's resources with a rogue AWS account - or share the resources with the entire internet 😈
☆188Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for endgame
- S3 Account Search☆245Updated 3 weeks ago
- Unauthenticated enumeration of AWS, Azure, and GCP Principals☆202Updated 3 months ago
- IAM-Deescalate helps mitigate privilege escalation risk in AWS identity and access management (IAM)☆96Updated 2 years ago
- A utility to convert your AWS CLI credentials into AWS console access.☆218Updated 4 years ago
- Resource types that can be publicly exposed on AWS☆316Updated 2 years ago
- Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).☆138Updated 7 months ago
- Hide from the InstanceCredentialExfiltration GuardDuty finding by using VPC Endpoints☆112Updated last year
- Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.☆477Updated 9 months ago
- Search exposed EBS volumes for secrets☆285Updated last year
- Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.☆265Updated last month
- An AWS IAM policy statement parser and query tool.☆156Updated 8 months ago
- IAMFinder enumerates and finds users and IAM roles in a target AWS account.☆109Updated 3 years ago
- Red Team Scripts for AWS.☆166Updated 4 years ago
- Find cloud assets that no one wants exposed 🔎 ☁️☆332Updated 4 years ago
- ☆125Updated 3 months ago
- Lightspin AWS IAM Vulnerability Scanner☆96Updated 3 years ago
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆133Updated 4 years ago
- Cloud-related research releases from the Rhino Security Labs team.☆355Updated 4 years ago
- Utility for downloading and mounting EBS snapshots using the EBS Direct API's☆73Updated last year
- OWASP Domain Protect - prevent subdomain takeover☆397Updated last month
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.☆62Updated 5 years ago
- ☆109Updated 3 weeks ago
- Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions☆235Updated 3 weeks ago
- sgCheckup generates nmap output based on scanning your AWS Security Groups for unexpected open ports.☆81Updated 3 years ago
- Route53/CloudFront Vulnerability Assessment Utility☆84Updated last year
- Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic☆280Updated last year
- Awesome list for cloud security related projects☆76Updated 2 years ago
- A toolset to juggle AWS roles for persistent access☆51Updated 2 months ago