andresriancho / enumerate-iamLinks
Enumerate the permissions associated with AWS credential set
☆1,185Updated last year
Alternatives and similar repositories for enumerate-iam
Users that are interested in enumerate-iam are comparing it to the libraries listed below
Sorting:
- Awesome cloud enumerator☆1,043Updated 6 months ago
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.☆1,924Updated 2 months ago
- WeirdAAL (AWS Attack Library)☆819Updated 8 months ago
- A collection of awesome AWS S3 tools that collects and enumerates exposed S3 buckets☆383Updated last year
- Leverages publicly available datasets from Google BigQuery to generate content discovery and subdomain wordlists☆748Updated 2 years ago
- Tool to check for dependency confusion vulnerabilities in multiple package management systems☆754Updated last year
- A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.☆536Updated 2 years ago
- Cloudlist is a tool for listing Assets from multiple Cloud Providers.☆971Updated 3 weeks ago
- S3 Account Search☆18Updated last month
- A tool that can help detect and takeover subdomains with dead DNS records☆766Updated 4 years ago
- Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.☆518Updated last week
- Pull out bits of URLs provided on stdin☆1,216Updated 2 years ago
- Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.☆871Updated 6 months ago
- Fast and stealthy Amazon S3 bucket enumeration tool for pentesters.☆254Updated last month
- A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure☆723Updated last year
- Security Tool to Look For Interesting Files in S3 Buckets☆1,431Updated last year
- Cloud-related research releases from the Rhino Security Labs team.☆391Updated 5 years ago
- Fast GitHub recon tool. Scans for exposed API keys across all of GitHub, not just known repos and orgs. Support for GitHub dorks.☆1,341Updated 2 months ago
- ☆1,024Updated this week
- A wordlist of API names for web application assessments☆846Updated 3 months ago
- Identify privilege escalation paths within and across different clouds☆701Updated 3 weeks ago
- ☆258Updated last year
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆633Updated 2 months ago
- A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..e…☆990Updated last year
- An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects☆963Updated 3 years ago
- 🍪 CookieMonster helps you detect and abuse vulnerable implementations of stateless sessions.☆911Updated 8 months ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆670Updated last year
- Find AWS S3 buckets and test their permissions.☆393Updated 2 years ago
- A collection of AWS penetration testing junk☆1,207Updated 2 years ago
- Scan for misconfigured S3 buckets across S3-compatible APIs!☆2,913Updated last week