SygniaLabs / security-cloud-scout
☆133Updated last year
Alternatives and similar repositories for security-cloud-scout:
Users that are interested in security-cloud-scout are comparing it to the libraries listed below
- ☆169Updated last year
- Recon tool for cloud provider attribution. Supports AWS, Azure, Google, Cloudflare, and Digital Ocean.☆164Updated 3 months ago
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated last year
- A tool to keep AWS pentests and red teams efficient, organized, and stealthy.☆89Updated 11 months ago
- This script is a multi-threaded Okta password sprayer.☆70Updated last year
- A Docker container for remote penetration testing.☆134Updated 3 years ago
- Supporting materials for my "Intelligence-Led Adversarial Threat Modelling with VECTR" workshop☆59Updated this week
- Resolves an IP address to the cloud provider it is hosted on☆94Updated last month
- This application was built to help reduce the amount of time it takes to review AWS Lambda code.☆60Updated 3 months ago
- A very simple lab to demo some Terraform, DSC, Inspec and Gitlab CI☆89Updated 2 years ago
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆135Updated 4 years ago
- Hide from the InstanceCredentialExfiltration GuardDuty finding by using VPC Endpoints☆113Updated last year
- ☆115Updated 3 years ago
- IAMFinder enumerates and finds users and IAM roles in a target AWS account.☆110Updated 4 years ago
- ☆33Updated last month
- Lateral Movement graph for Azure Active Directory☆122Updated 2 years ago
- Microsoft Azure Exploitation Framework☆56Updated 3 years ago
- ☆23Updated last year
- ☆93Updated 2 years ago
- ☆58Updated last year
- GCP GOAT is the vulnerable application for learn the GCP Security☆63Updated last year
- GoldenSAML Attack Libraries and Framework☆67Updated 8 months ago
- CONVEX is a group of CTFs that are independently deployable into participant Azure environments.☆137Updated 2 years ago
- POC code to explore phishing attacks using OAuth 2.0 authorization flows, such as the device authorization grant.☆34Updated 3 years ago
- Determine privileges from cloud credentials via brute-force testing.☆66Updated 5 months ago
- ☆69Updated 3 years ago
- 🖇️ STRIDE vs. ASVS equivalence table☆75Updated 5 months ago
- Script samples from the book Pentesting Azure Applications (2018, No Starch Press)☆88Updated 6 years ago
- List of Red Team Resources☆17Updated 4 years ago
- A public cloud security knowledgebase - https://www.secwiki.cloud/☆51Updated 3 months ago