aws / http-desync-guardian
Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).
☆265Updated 4 years ago
Alternatives and similar repositories for http-desync-guardian
Users that are interested in http-desync-guardian are comparing it to the libraries listed below
Sorting:
- A command line interface for Amazon EBS snapshots☆223Updated this week
- Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).☆143Updated 2 weeks ago
- Resource types that can be publicly exposed on AWS☆327Updated 3 years ago
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.☆64Updated 5 years ago
- k8s audit repo☆228Updated 5 years ago
- OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws☆326Updated 9 months ago
- No need for IAM users when we have Yubikeys☆158Updated 3 years ago
- ☆137Updated 2 months ago
- Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.☆545Updated 4 months ago
- Automatically compile an AWS Service Control Policy that ONLY allows AWS services that are compliant with your preferred compliance frame…☆225Updated last year
- AWS Identity and Access Management Visualizer and Anomaly Finder☆295Updated 10 months ago
- A centralized source of all AWS IAM privilege escalation methods released by Rhino Security Labs.☆912Updated 5 years ago
- Documenting your Threat Models with HCL☆427Updated this week
- Rust libraries and tools for using and generating TUF repositories☆213Updated this week
- ☆156Updated last year
- Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)☆439Updated last year
- Security aspects of AWS products for the Security Specialist certification☆210Updated 3 years ago
- AWS Inventory and Compliance Framework☆224Updated last year
- OWASP Domain Protect - prevent subdomain takeover☆397Updated 4 months ago
- Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.☆271Updated 7 months ago
- AWS Security Tools (AST) in a simple Docker container.☆287Updated 3 years ago
- Parse and Process AWS IAM Policies, Statements, ARNs, and wildcards.☆441Updated 10 months ago
- ☆217Updated 5 months ago
- S3 Account Search☆4Updated 7 months ago
- DEPRECATED - web security checklist for Firefox Services☆74Updated 4 years ago
- Aardvark is a multi-account AWS IAM Access Advisor API☆477Updated 6 months ago
- List of known AWS accounts☆209Updated last week
- List of vendors that do not allow IMDSv2 enforcement☆141Updated last year
- Research on the enumeration of IAM permissions without logging to CloudTrail☆61Updated 3 years ago
- AWS docs, guides, and other tools☆76Updated 2 years ago