TinderSec / oidc-scanner-aws
☆48Updated 2 years ago
Alternatives and similar repositories for oidc-scanner-aws:
Users that are interested in oidc-scanner-aws are comparing it to the libraries listed below
- find dangling domains in a multi cloud environment☆141Updated last week
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis tool☆40Updated last year
- AWS honey token manager☆87Updated 8 months ago
- A tool to uncover undocumented APIs from the AWS Console.☆101Updated 4 months ago
- An IAM Simulator that outputs detailed explains of how a request was evaluated.☆74Updated this week
- Protect against subdomain takeover☆93Updated 10 months ago
- Vulnerable by Design AWS Cloud Development Kit (CDK) Infrastructure☆47Updated last year
- A collection of documented and undocumented AWS API models☆33Updated 5 months ago
- Safer AWS SCP deployments via real-time monitoring☆50Updated last year
- An AWS metadata enumeration tool by Plerion☆96Updated last year
- ☆165Updated 7 months ago
- A tool for quickly evaluating IAM permissions in AWS.☆73Updated 10 months ago
- Crowdsourced list of sensitive IAM Actions☆144Updated 5 months ago
- ☆116Updated 3 weeks ago
- Analyzes CloudTrail data of a given AWS account and generates a summary of recently active IAM principals, API calls they made, as well a…☆160Updated this week
- AWS SSO Reporter☆54Updated last year
- A Terraform module that makes it a snap to opt out of all AWS AI/ML data harvesting.☆30Updated last year
- Clean accounts over permissions in GCP infra at scale☆71Updated last year
- Compares and analyzes GCP IAM roles.☆77Updated last month
- A Golang program to rotate AWS & GCP account keys☆65Updated last month
- An AWS IAM policy statement parser and query tool.☆175Updated last year
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆53Updated 2 months ago
- ☆44Updated 3 months ago
- Semgrep-based Policy Controller for Kubernetes☆47Updated last week
- Scan publicly accessible assets on your AWS cloud environment☆139Updated 10 months ago
- A cloud security tool to search and clean up unused AWS access keys, written in Go.☆49Updated 2 years ago
- A multi-vault secret injection tool for safely injecting secrets into app environment☆123Updated 3 weeks ago
- ☆48Updated 5 months ago
- Unauthenticated enumeration of AWS, Azure, and GCP Principals☆224Updated 5 months ago