appsecco / CloudPentestCheatsheets
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
☆22Updated 4 years ago
Alternatives and similar repositories for CloudPentestCheatsheets:
Users that are interested in CloudPentestCheatsheets are comparing it to the libraries listed below
- ☆27Updated 5 years ago
- A tool for testing objects' permissions in AWS buckets☆41Updated 3 years ago
- A collection of slides, videos, and proof-of-concept scripts from various Rhino presentations.☆37Updated 6 years ago
- AWS Security Checks☆36Updated 7 years ago
- Pivot into private VPC networks using a VPN connection☆41Updated 5 years ago
- AWS S3 Sensitive Data Search☆35Updated 3 years ago
- Repository for all the workshop content delivered at nullcon X on 1st of March 2019☆81Updated 5 years ago
- A tool to evaluate Content Security Policies.☆70Updated 4 years ago
- A collection of tools to find data that has been made public in cloud storage systems such as S3 Buckets and Digital Ocean Spaces☆72Updated 2 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆62Updated last year
- Monitoring GitHub for sensitive data shared publicly☆66Updated 3 years ago
- ☆90Updated 2 years ago
- Virtual Security Operations Center☆50Updated last year
- Burp Suite Importer - Connect to multiple web servers while populating the sitemap.☆48Updated 4 years ago
- Scripts and tools for AWS Pentest☆51Updated 4 years ago
- Preventing malicious takeover of the retired slurp AWS tool☆40Updated 6 years ago
- A simple file-based scanner to look for potential AWS access and secret keys in files☆89Updated 10 months ago
- Extensive code infrastructure for finding unintended information leaks in files, git repositories and much more.☆28Updated 2 years ago
- A tool to enumerate S3 buckets manually or via certstream☆80Updated last year
- Report and finding templates used by the Serpico reporting tool☆16Updated 6 years ago
- Appsecco training course content on Attacking and Auditing Dockers Containers and Kubernetes Clusters☆14Updated 4 years ago
- An nmap script to produce target lists for use with various tools.☆33Updated 3 years ago
- This is a set of tips and reminders for pentesting processes and scripts/programs. Initially for personal use, but if anyone else finds t…☆52Updated 4 years ago
- All-in-one AWS S3 bucket tool for pentesters.☆72Updated 5 years ago
- Amazon bucket brute force tool☆95Updated 11 years ago
- This repository contains all the material from the talk "Practical recon techniques for bug hunters & pentesters" given at Bugcrowd Level…☆60Updated 6 years ago
- Jekyll Files for cloudsecwiki.com☆50Updated 3 years ago
- Where I'll be posting my scripts, guides, cheatsheets, and notes for for my OSCP journey.☆32Updated 7 years ago
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆135Updated 4 years ago
- Dictionary cracking tool for HTTP Digest challenge/response hashes☆29Updated last year