aws / http-desync-guardian
Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).
☆258Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for http-desync-guardian
- A command line interface for Amazon EBS snapshots☆199Updated 2 weeks ago
- Resource types that can be publicly exposed on AWS☆317Updated 2 years ago
- AWS Serverless Security☆400Updated 2 years ago
- Library and CLI tool for analysing CloudFormation templates and check them for security compliance.☆399Updated last week
- for AWS Security material☆245Updated 2 years ago
- Automatically compile an AWS Service Control Policy that ONLY allows AWS services that are compliant with your preferred compliance frame…☆224Updated last year
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.☆62Updated 5 years ago
- Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)☆436Updated last year
- OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws☆318Updated 3 months ago
- ☆151Updated last year
- A tool for identifying misconfigured CloudFront domains☆346Updated 4 years ago
- Aardvark is a multi-account AWS IAM Access Advisor API☆472Updated 2 weeks ago
- S3 Account Search☆245Updated 3 weeks ago
- Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services☆634Updated 3 years ago
- The ConsoleMe CLI utility☆322Updated 5 months ago
- Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).☆138Updated 7 months ago
- Tools for fingerprinting and exploiting Amazon cloud infrastructures☆445Updated 2 years ago
- ☆117Updated 2 months ago
- Security aspects of AWS products for the Security Specialist certification☆208Updated 2 years ago
- Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.☆528Updated 7 months ago
- No need for IAM users when we have Yubikeys☆158Updated 2 years ago
- A centralized source of all AWS IAM privilege escalation methods released by Rhino Security Labs.☆897Updated 5 years ago
- Identity & Access Management simplified and secure.☆249Updated last year
- A crowdsourced AWS IAM permissions reference.☆89Updated last month
- AWS Security Tools (AST) in a simple Docker container.☆283Updated 3 years ago
- ☆203Updated last month
- A project to collate IAM actions, AWS APIs and managed policies from various public sources.☆285Updated this week
- Cloud-related research releases from the Rhino Security Labs team.☆355Updated 4 years ago