Permiso-io-tools / RansomWhen
RansomWhen is a tool to enumerate identities that can lock S3 Buckets using KMS, resulting in ransomwares, as well as detect occurances of S3 Ransomwares using KMS
☆41Updated last month
Alternatives and similar repositories for RansomWhen:
Users that are interested in RansomWhen are comparing it to the libraries listed below
- IMDSPOOF is a cyber deception tool that spoofs the AWS IMDS service to return HoneyTokens that can be alerted on.☆101Updated last year
- ☆16Updated 4 months ago
- Independently deploy customized honeyservices in AWS to trigger alerts on unauthorized access. It utilizes a dedicated CloudTrail for pre…☆51Updated 4 months ago
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆36Updated 6 months ago
- AWS IAM Username Enumerator and Password Spraying Tool in Python3☆75Updated last month
- ☆21Updated 3 weeks ago
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments☆138Updated 2 months ago
- Hijack a slack bot to phish your way in☆55Updated 3 months ago
- This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits containing potential secret or interesting…☆46Updated 7 months ago
- An LLM and OCR based Indicator of Compromise Extraction Tool☆33Updated 3 months ago
- Offensive Kubernetes Threat Matrix -- kubenomicon.com☆38Updated 2 months ago
- A PoC to Simulate Ransomware Attack on AWS Environment☆30Updated 5 months ago
- DeRF (Detection Replay Framework) is an "Attacks As A Service" framework, allowing the emulation of offensive techniques and generation o…☆91Updated last year
- Repository that contains a set of purposefully erroneous Yara rules.☆50Updated last year
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆104Updated 4 months ago
- Simple Workspace Attack Tool (SWAT) is a tool for simulating malicious behavior against Google Workspace in reference to the MITRE ATT&CK…☆164Updated 5 months ago
- gubble is a tool designed to audit Google Workspace group settings. It analyzes settings such as who can join, view membership, post mess…☆45Updated 2 months ago
- ☆45Updated 9 months ago
- Addon for BHCE☆40Updated last week
- When good OAuth apps go rogue. Documents observed OAuth application tradecraft☆69Updated 2 months ago
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated last year
- ☆33Updated 3 months ago
- ☆34Updated 3 months ago
- Framework for Monitoring File Ingestion Source for Yara Matches☆45Updated 2 weeks ago
- AHHHZURE is an automated deployment script that creates a vulnerable Azure cloud lab for offensive security practitioners and enthusiasts…☆102Updated 11 months ago
- ☆40Updated 7 months ago
- Collection of Docker honeypot logs from 2021 - 2024☆36Updated 5 months ago
- Cloud Offensive Breach and Risk Assessment (COBRA) Tool☆88Updated last month
- Living Off Security Tools☆45Updated 4 months ago
- A comprehensive knowledge base for security professionals to keep track of and build defenses against API attack techniques.☆42Updated 6 months ago