appsecco / CloudPentestCheatsheetsLinks
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
☆22Updated 5 years ago
Alternatives and similar repositories for CloudPentestCheatsheets
Users that are interested in CloudPentestCheatsheets are comparing it to the libraries listed below
Sorting:
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆134Updated 5 years ago
- AWS Security Checks☆40Updated 7 years ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆49Updated 6 years ago
- Repository for all the workshop content delivered at nullcon X on 1st of March 2019☆81Updated 6 years ago
- A simple file-based scanner to look for potential AWS access and secret keys in files☆93Updated last year
- Scripts and tools for AWS Pentest☆53Updated 5 years ago
- Route53/CloudFront Vulnerability Assessment Utility☆87Updated 2 years ago
- Monitoring GitHub for sensitive data shared publicly☆66Updated 3 years ago
- Cloud Security Operations Orchestrator☆188Updated last year
- Hayat is a script for report and analyze Google Cloud Platform resources.☆81Updated 5 years ago
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆78Updated 4 years ago
- Amazon bucket brute force tool☆102Updated 12 years ago
- IAMFinder enumerates and finds users and IAM roles in a target AWS account.☆111Updated 5 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆106Updated last year
- A tool geared towards pentesting APIs using OpenAPI definitions.☆182Updated 3 years ago
- ☆28Updated 6 years ago
- A collection of tools to find data that has been made public in cloud storage systems such as S3 Buckets and Digital Ocean Spaces☆80Updated last month
- A tool to enumerate S3 buckets manually or via certstream☆82Updated 2 years ago
- 🏰 A Python script for AWS S3 bucket enumeration.☆146Updated 2 years ago
- Weaponizing Live CT logs for automated monitoring of assets☆134Updated 4 years ago
- Resources to learn cloud environment and pentesting the same, contains AWS, Azure, Google Cloud☆54Updated 3 years ago
- OWASP practice lab, just a few copy/pastes away. Fully stacked and ready to go with Docker☆19Updated 7 years ago
- Deploy a Private Burpsuite Collaborator using boto3 Python Library☆58Updated 5 years ago
- This is an offensive guide to securing AWS infrastructures. The hope is that by knowing how to take advantage of various types of AWS wea…☆173Updated 6 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆78Updated 3 years ago
- ☆90Updated 3 years ago
- ☆51Updated 3 years ago
- ☆72Updated 5 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆65Updated 2 years ago
- Pentesting/Bugbounty Dockerfiles.☆177Updated 4 years ago