TinderSec / oidc-scanner-aws
☆47Updated last year
Alternatives and similar repositories for oidc-scanner-aws:
Users that are interested in oidc-scanner-aws are comparing it to the libraries listed below
- find dangling domains in a multi cloud environment☆140Updated this week
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆60Updated last year
- AWS honey token manager☆87Updated 6 months ago
- An IAM Simulator that outputs detailed explains of how a request was evaluated.☆69Updated this week
- A tool to uncover undocumented APIs from the AWS Console.☆95Updated 3 months ago
- Crowdsourced list of sensitive IAM Actions☆141Updated 3 months ago
- Safer AWS SCP deployments via real-time monitoring☆50Updated last year
- ☆134Updated 3 weeks ago
- An AWS metadata enumeration tool by Plerion☆87Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis tool☆39Updated last year
- ☆157Updated 3 weeks ago
- Vulnerable by Design AWS Cloud Development Kit (CDK) Infrastructure☆46Updated last year
- An AWS IAM policy statement parser and query tool.☆173Updated last year
- Protect against subdomain takeover☆92Updated 8 months ago
- A collection of documented and undocumented AWS API models☆32Updated 3 months ago
- A Terraform module that makes it a snap to opt out of all AWS AI/ML data harvesting.☆30Updated last year
- AWS Attack Path Management Tool - Walking on the Moon☆235Updated 2 months ago
- A tool for quickly evaluating IAM permissions in AWS.☆72Updated 8 months ago
- A cloud security tool to search and clean up unused AWS access keys, written in Go.☆50Updated 2 years ago
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆101Updated 3 months ago
- A multi-vault secret injection tool for safely injecting secrets into app environment☆116Updated 2 weeks ago
- ☆163Updated 5 months ago
- Scan publicly accessible assets on your AWS cloud environment☆139Updated 8 months ago
- ☆112Updated last month
- AWS SSO Reporter☆54Updated last year
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆52Updated 3 weeks ago
- Clean accounts over permissions in GCP infra at scale☆71Updated last year
- Independently deploy customized honeyservices in AWS to trigger alerts on unauthorized access. It utilizes a dedicated CloudTrail for pre…☆47Updated 3 months ago
- Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).☆141Updated 11 months ago