Pr0teus / aws-trail-reconLinks
AWS Trail Recon is an idea that came up during gohacking's offensive AWS security training. The idea is to use cloudtrail:lookupevents to analyze what permissions the user of the leaked key has
☆15Updated last year
Alternatives and similar repositories for aws-trail-recon
Users that are interested in aws-trail-recon are comparing it to the libraries listed below
Sorting:
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities☆31Updated last month
- A multi-cloud DNS record scanner that aims to help cybersecurity/IT analysts identify dangling CNAME records in their cloud DNS services …☆50Updated 2 years ago
- HazProne is a Cloud Pentesting Framework that emulates close to Real-World Scenarios by deploying Vulnerable-By-Demand AWS resources enab…☆40Updated 3 years ago
- Manage attack surface data on Elasticsearch☆23Updated 2 years ago
- Simple PoC for demonstrating Race Conditions on Websockets☆55Updated 2 years ago
- Some of my rough notes for Docker threat detection☆48Updated 2 years ago
- ☆16Updated 4 months ago
- ☆27Updated 2 years ago
- GATOR - GCP Attack Toolkit for Offensive Research, a tool designed to aid in research and exploiting Google Cloud Environments☆89Updated last year
- A Project dedicated to documenting various attack and detection vectors that can be encountered within Google Cloud Platform (GCP).☆59Updated last year
- A BurpSuite extension to deploy an OpenVPN config file to DigitalOcean and set up a SOCKS proxy to route traffic through it☆51Updated last month
- EC2StepShell is an AWS post-exploitation tool for getting high privileges reverse shells in public or private EC2 instances.☆68Updated last year
- A tool for quickly evaluating IAM permissions in AWS.☆60Updated 2 years ago
- A simple web app to get the latest EPSS data for a CVE ID☆11Updated 2 weeks ago
- Comprehensive AWS cloud reconnaissance and privilege escalation toolkit written in Python. Features IAM, EC2, S3, Lambda, ECS, Secrets Ma…☆48Updated 5 months ago
- ☆50Updated last year
- Monitor your target continuously for new subdomains!☆25Updated 2 years ago
- "Terrible Thick Client" is a vulnerable application developed in C# .NET framework.☆20Updated 2 years ago
- An MCP Server for Pwndoc (Pentesting Reporting Tool)☆22Updated last week
- Exploits Unauth Docker API☆43Updated 8 months ago
- moniorg is a tool that leverages crt.sh website to monitor domains of a target☆47Updated 2 years ago
- List of MurmurHash3 favicon hashes of widely used technologies by vendor to search with Shodan.☆35Updated last year
- Collection of Tools & Techniques for analyzing URLs☆32Updated 2 years ago
- A National Vulnerability Database (NVD) API query tool☆17Updated 2 years ago
- This repository contains scripts about ACL abuse and any other active directory attacking methods.☆37Updated 2 years ago
- ☆31Updated 2 years ago
- aws cli pentesting/red team snippets☆32Updated last year
- ☆76Updated last year
- A graphical automation to monitor if backdoors/default settings are still active on the compromised machines over time.☆44Updated last year
- DelePwn is a security assessment tool designed to identify and demonstrate the risks associated with Google Workspace Domain-Wide Delegat…☆37Updated 4 months ago