NicholasSpringer / thunder-ctfLinks
GCP cloud security CTF
☆47Updated 2 months ago
Alternatives and similar repositories for thunder-ctf
Users that are interested in thunder-ctf are comparing it to the libraries listed below
Sorting:
- GCP GOAT is the vulnerable application for learn the GCP Security☆67Updated 4 months ago
- Blogpost series showcasing interesting cloud - web app security bugs☆49Updated 2 years ago
- ☆38Updated last month
- Enumerate AWS permissions and resources.☆70Updated 3 years ago
- ☆24Updated 2 years ago
- Determine privileges from cloud credentials via brute-force testing.☆69Updated last year
- HazProne is a Cloud Pentesting Framework that emulates close to Real-World Scenarios by deploying Vulnerable-By-Demand AWS resources enab…☆40Updated 3 years ago
- ☆139Updated 2 years ago
- Virtual Security Operations Center☆51Updated 2 years ago
- ☆94Updated 2 years ago
- ☆36Updated 5 years ago
- Jenkins Security Research or Hacking Jenkins ;)☆11Updated 9 months ago
- Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, an…☆144Updated 2 years ago
- ☆60Updated 2 years ago
- Use the GCP testIamPermissions functionality to bruteforce and discover your permissions☆40Updated 2 months ago
- ☆70Updated 2 years ago
- ☆50Updated last year
- Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups☆60Updated 2 years ago
- Slackhound allows red and blue teams to perform fast reconnaissance on Slack workspaces/organizations to quickly search user profiles, lo…☆82Updated last month
- A multi-cloud DNS record scanner that aims to help cybersecurity/IT analysts identify dangling CNAME records in their cloud DNS services …☆50Updated 2 years ago
- Posts about different topics☆40Updated last month
- Slides and materials for conference presentations☆11Updated 2 years ago
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated 2 years ago
- ☆113Updated 2 years ago
- Publicly availalbe vulnarble by desgin vm/machines☆42Updated 3 years ago
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities☆29Updated 5 months ago
- ☆48Updated 9 months ago
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.☆32Updated 3 years ago
- Appsecco training course content on Attacking and Auditing Dockers Containers and Kubernetes Clusters☆15Updated 5 years ago
- cvet is a Python utility for pulling actionable vulnerabilities from cvetrends.com☆39Updated 3 years ago