agnivesh / endgame
An AWS Pentesting tool that lets you use one-liner commands to backdoor an AWS account's resources with a rogue AWS account - or share the resources with the entire internet π
β269Updated 4 years ago
Alternatives and similar repositories for endgame:
Users that are interested in endgame are comparing it to the libraries listed below
- A honey token manager and alert system for AWS.β319Updated 3 years ago
- AWS Security Tools (AST) in a simple Docker container.β287Updated 3 years ago
- Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.β541Updated 2 months ago
- rpCheckup is an AWS resource policy security checkup tool that identifies public, external account access, intra-org account access, β¦β160Updated 3 years ago
- AWS Identity and Access Management Visualizer and Anomaly Finderβ293Updated 9 months ago
- Access Undenied parses AWS AccessDenied CloudTrail events, explains the reasons for them, and offers actionable remediation steps. Open-sβ¦β262Updated 2 years ago
- Resource types that can be publicly exposed on AWSβ324Updated 3 years ago
- Automatically compile an AWS Service Control Policy that ONLY allows AWS services that are compliant with your preferred compliance frameβ¦β225Updated last year
- Red Team Scripts for AWS.β168Updated 4 years ago
- Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).β141Updated last year
- AWS Inventory and Compliance Frameworkβ224Updated last year
- AWS CloudSaga - Simulate security events in AWSβ451Updated this week
- [MAMIP] Monitor AWS Managed IAM Policies Changesβ480Updated this week
- OWASP Domain Protect - prevent subdomain takeoverβ401Updated 3 months ago
- An AWS tool to help you create a point in time assessment of your AWS account using Prowler.β533Updated last month
- A command-line tool to get valuable information out of AWS CloudTrailβ810Updated this week
- Identity & Access Management simplified and secure.β252Updated 2 years ago
- Run individual controls or full compliance benchmarks for CIS, PCI, NIST, HIPAA and more across all of your AWS accounts using Powerpipe β¦β384Updated this week
- A graph-based tool for visualizing effective access and resource relationships in AWS environments.β937Updated 2 years ago
- Is your AWS perimeter secure? Use Powerpipe and Steampipe to check your AWS accounts for public resources, resources shared with untrustβ¦β111Updated 4 months ago
- Scan publicly accessible assets on your AWS cloud environmentβ139Updated 9 months ago
- Open source application to instantly remediate common security issues through the use of AWS Configβ221Updated 4 years ago
- AWS Organizations Service Control Policies (SCPs) written in HashiCorp Terraform.β237Updated 5 months ago
- Unauthenticated enumeration of AWS, Azure, and GCP Principalsβ222Updated 4 months ago
- Open Cloud Security Posture Management Engineβ337Updated 3 years ago
- List of known AWS accountsβ188Updated this week
- Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)β438Updated last year
- CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies.β892Updated 3 years ago
- A project to collate IAM actions, AWS APIs and managed policies from various public sources.β292Updated this week
- Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS servicesβ638Updated 3 years ago