appsecco / CloudPentestCheatsheetsLinks
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
☆22Updated 5 years ago
Alternatives and similar repositories for CloudPentestCheatsheets
Users that are interested in CloudPentestCheatsheets are comparing it to the libraries listed below
Sorting:
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆134Updated 5 years ago
- AWS Security Checks☆40Updated 8 years ago
- Scripts and tools for AWS Pentest☆53Updated 5 years ago
- A simple file-based scanner to look for potential AWS access and secret keys in files☆94Updated last year
- Pentesting/Bugbounty Dockerfiles.☆176Updated 4 years ago
- Repository for all the workshop content delivered at nullcon X on 1st of March 2019☆80Updated 6 years ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆49Updated 6 years ago
- This is an offensive guide to securing AWS infrastructures. The hope is that by knowing how to take advantage of various types of AWS wea…☆174Updated 6 years ago
- Hands-On AWS Penetration Testing with Kali Linux published by Packt☆135Updated 3 years ago
- Monitoring GitHub for sensitive data shared publicly☆66Updated 4 years ago
- OWASP practice lab, just a few copy/pastes away. Fully stacked and ready to go with Docker☆21Updated 7 years ago
- Resources to learn cloud environment and pentesting the same, contains AWS, Azure, Google Cloud☆55Updated 3 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆110Updated 2 years ago
- Route53/CloudFront Vulnerability Assessment Utility☆87Updated 2 years ago
- AWS S3 Bucket/Object Finder☆123Updated 4 years ago
- Cloud Security Operations Orchestrator☆188Updated last year
- Damn Vulnerable Cloud Application☆206Updated 7 years ago
- Amazon bucket brute force tool☆102Updated 12 years ago
- A tool geared towards pentesting APIs using OpenAPI definitions.☆183Updated 3 years ago
- Hayat is a script for report and analyze Google Cloud Platform resources.☆81Updated 6 years ago
- A tool to enumerate S3 buckets manually or via certstream☆82Updated 2 years ago
- ☆29Updated 6 years ago
- A lab to play with authentication and authorisation problems☆98Updated 2 years ago
- pentest-standard.org docs redesign☆47Updated 3 years ago
- A Repository dedicated to creating modular and automated penetration testing frameworks utilizing Jupyter Notebooks☆148Updated 5 years ago
- 🏰 A Python script for AWS S3 bucket enumeration.☆145Updated 3 years ago
- A collection of tools to find data that has been made public in cloud storage systems such as S3 Buckets and Digital Ocean Spaces☆82Updated 3 months ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆66Updated 2 years ago
- A collection of response templates for invalid bug bounty reports.☆90Updated 7 years ago
- Preventing malicious takeover of the retired slurp AWS tool☆41Updated 7 years ago