This repository is in progress, it will keep updating as I come across to new learning materials. Feel free to contribute.
☆221Sep 3, 2022Updated 3 years ago
Alternatives and similar repositories for Cloud-Pentesting
Users that are interested in Cloud-Pentesting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆23Jun 30, 2021Updated 5 years ago
- ☆760Aug 26, 2022Updated 3 years ago
- PDF slides☆246Aug 19, 2021Updated 4 years ago
- ☆537Jul 16, 2021Updated 5 years ago
- Azure Security Resources and Notes☆1,772Feb 17, 2026Updated 6 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Template used for my OSCP exam.☆30Aug 9, 2022Updated 4 years ago
- Subdomain takeover scanner using Python asyncio☆18Oct 24, 2022Updated 3 years ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,835Apr 6, 2026Updated 4 months ago
- A collection of GCP IAM privilege escalation methods documented by the Rhino Security Labs team.☆425Oct 6, 2025Updated 10 months ago
- Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions☆53Dec 21, 2021Updated 4 years ago
- ☆34Jun 23, 2021Updated 5 years ago
- ☆142Jul 9, 2021Updated 5 years ago
- ☆48Feb 21, 2021Updated 5 years ago
- Azure Red Team tool for graphing Azure and Azure Active Directory objects☆1,713Jan 8, 2024Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Complite Web Application Penetration Testing☆28Jul 9, 2021Updated 5 years ago
- Mind-Maps of Several Things☆2,725Jun 29, 2023Updated 3 years ago
- Wounty is a simple web enumeration script that makes use of other popular tools to automate the early stages of recognition in Bug Bounty…☆14Feb 6, 2022Updated 4 years ago
- vulnerable OAuth 2.0 applications: understand the security implications of your OAuth 2.0 decisions.☆332Mar 27, 2024Updated 2 years ago
- a mindmap on pentest #pentestmindmap #oscp #lpt #ecsa #ceh #bugbounty☆348Jun 27, 2025Updated last year
- 🛡️ Awesome Cloud Security Resources ⚔️☆2,477Mar 17, 2026Updated 5 months ago
- A tool to parse, deduplicate, and query multiple port scans.☆60Aug 11, 2023Updated 3 years ago
- A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.☆184Nov 22, 2021Updated 4 years ago
- Awesome list of step by step techniques to achieve Remote Code Execution on various apps!☆1,940Oct 7, 2023Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- My nots from Web application Hacker's Handbook☆18Nov 22, 2021Updated 4 years ago
- Any presentation we've given at FortyNorth Security☆33Sep 27, 2021Updated 4 years ago
- Resources to learn cloud environment and pentesting the same, contains AWS, Azure, Google Cloud☆57Mar 7, 2022Updated 4 years ago
- ☆10Dec 8, 2022Updated 3 years ago
- Python utility to takeover domains vulnerable to AWS NS Takeover☆86Feb 2, 2023Updated 3 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Sep 6, 2021Updated 4 years ago
- SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to crea…☆546Aug 4, 2022Updated 4 years ago
- ☆87May 27, 2021Updated 5 years ago
- Search for secrets inside user data attached to EC2 instances on multiple AWS accounts☆16Jun 19, 2024Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Given a list of domains, you resolve them and get the IP addresses.☆48Mar 2, 2022Updated 4 years ago
- ☆245Jun 10, 2021Updated 5 years ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆986Dec 31, 2021Updated 4 years ago
- this repository is a base so everyone can modify it according to there thoughts and process used☆10Jun 9, 2021Updated 5 years ago
- Pass the Hash to a named pipe for token Impersonation☆145May 1, 2021Updated 5 years ago
- A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.☆2,020Sep 5, 2021Updated 4 years ago
- SSRF (Server Side Request Forgery) testing resources☆2,505Oct 12, 2024Updated last year