doyensec / cloudsec-tidbits
Blogpost series showcasing interesting cloud - web app security bugs
☆47Updated last year
Alternatives and similar repositories for cloudsec-tidbits:
Users that are interested in cloudsec-tidbits are comparing it to the libraries listed below
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated last year
- Determine privileges from cloud credentials via brute-force testing.☆66Updated 5 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆40Updated last year
- ☆42Updated 8 months ago
- ☆58Updated last year
- This repository hosts several snippets and file related to the BsidesLV 2024 talk about Shadow and Zombie APIs by me☆17Updated 6 months ago
- A public cloud security knowledgebase - https://www.secwiki.cloud/☆51Updated 3 months ago
- ☆55Updated last year
- GCP GOAT is the vulnerable application for learn the GCP Security☆63Updated last year
- HazProne is a Cloud Pentesting Framework that emulates close to Real-World Scenarios by deploying Vulnerable-By-Demand AWS resources enab…☆39Updated 2 years ago
- ☆17Updated 2 years ago
- An Evil OIDC Server☆53Updated 2 years ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆101Updated 3 weeks ago
- ☆20Updated last year
- A multi-cloud DNS record scanner that aims to help cybersecurity/IT analysts identify dangling CNAME records in their cloud DNS services …☆49Updated last year
- Enumerate AWS permissions and resources.☆67Updated 2 years ago
- A PoC to Simulate Ransomware Attack on AWS Environment☆30Updated 4 months ago
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆28Updated last month
- 📚A curated list of product security resources.☆19Updated 2 years ago
- ☆33Updated 2 months ago
- A tool to keep AWS pentests and red teams efficient, organized, and stealthy.☆89Updated 11 months ago
- Tool to spray AWS Console IAM Logins☆27Updated 2 years ago
- 🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends☆71Updated last year
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated 2 months ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆31Updated last year
- A GitHub Actions Supply Chain CTF / Goat☆17Updated 2 weeks ago
- Additional active scan checks for BURP☆26Updated 4 months ago
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆101Updated 3 months ago
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆36Updated 4 months ago
- GCP cloud security CTF☆42Updated 11 months ago