appsecco / CloudPentestCheatsheetsLinks
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
☆22Updated 5 years ago
Alternatives and similar repositories for CloudPentestCheatsheets
Users that are interested in CloudPentestCheatsheets are comparing it to the libraries listed below
Sorting:
- Scripts and tools for AWS Pentest☆53Updated 4 years ago
- Repository for all the workshop content delivered at nullcon X on 1st of March 2019☆81Updated 6 years ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆49Updated 5 years ago
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆134Updated 5 years ago
- AWS Security Checks☆39Updated 7 years ago
- Monitoring GitHub for sensitive data shared publicly☆66Updated 3 years ago
- A collection of tools to find data that has been made public in cloud storage systems such as S3 Buckets and Digital Ocean Spaces☆75Updated 3 years ago
- ☆28Updated 6 years ago
- A simple file-based scanner to look for potential AWS access and secret keys in files☆93Updated last year
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆103Updated last year
- Amazon bucket brute force tool☆102Updated 12 years ago
- A tool to evaluate Content Security Policies.☆72Updated 5 years ago
- Virtual Security Operations Center☆51Updated last year
- Pentesting/Bugbounty Dockerfiles.☆177Updated 4 years ago
- Pivot into private VPC networks using a VPN connection☆43Updated 5 years ago
- retrive metadata endpoint data with these one liners.☆38Updated 4 years ago
- Route53/CloudFront Vulnerability Assessment Utility☆86Updated last year
- A tool to enumerate S3 buckets manually or via certstream☆82Updated 2 years ago
- random notes☆46Updated last week
- A Collection of Email and Landing Page Templates for Use with Gophish☆30Updated 7 years ago
- A collection of slides, videos, and proof-of-concept scripts from various Rhino presentations.☆38Updated 6 years ago
- AWS S3 Sensitive Data Search☆36Updated 3 years ago
- A Modular Framework for the Automated Vulnerability Analysis in IP-based Networks☆66Updated 3 years ago
- Containerized version of my fork of Nahamsec's Lazyrecon.☆49Updated last week
- Jekyll Files for cloudsecwiki.com☆50Updated 3 years ago
- A lab to play with authentication and authorisation problems☆96Updated 2 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆63Updated 2 years ago
- A place to store my own wordlists, and link to others that are useful☆108Updated last year
- Reconnaissance tool for GitLab and GitHub organizations☆50Updated last year
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆78Updated 4 years ago