Blogpost series showcasing interesting cloud - web app security bugs
☆75Jul 20, 2026Updated 3 weeks ago
Alternatives and similar repositories for cloudsec-tidbits
Users that are interested in cloudsec-tidbits are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Simple CVE-2022-39299 PoC exploit generator to bypass authentication in SAML SSO Integrations using vulnerable versions of passport-sam…☆19Feb 8, 2023Updated 3 years ago
- The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2…☆61Jul 23, 2026Updated 2 weeks ago
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆31Jul 23, 2026Updated 2 weeks ago
- An Evil OIDC Server☆53Oct 19, 2022Updated 3 years ago
- Exploit for CVE-2024-0402 in Gitlab☆15Mar 18, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆111Jan 30, 2025Updated last year
- Go module that returns supported regions for a service or supported services for a region☆18Dec 12, 2025Updated 7 months ago
- Clean accounts over permissions in GCP infra at scale☆72May 9, 2023Updated 3 years ago
- PoC's and Slides from 'Gophers, whales and.. clouds? Oh my!' BSides Wellington presentation by Glenn 'devalias' Grant☆17Mar 3, 2018Updated 8 years ago
- Autonomous AI C2☆33Jul 23, 2024Updated 2 years ago
- Proof-of-Concept to evade auditd by writing /proc/PID/mem☆24Aug 21, 2023Updated 2 years ago
- PyBurp is a Burp Suite extension that provides predefined Python functions for HTTP/WebSocket traffic modification, context menu registra…☆38Apr 24, 2026Updated 3 months ago
- serverless url-shortener☆12Aug 25, 2024Updated last year
- this is everything☆41Apr 7, 2026Updated 4 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆11Sep 1, 2023Updated 2 years ago
- Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.☆57Updated this week
- Security configuration scanner for Claude Code☆45Updated this week
- PoC for CVE-Requested vulnerability in Amazon ECS (EC2 launch type) allowing cross-task IAM credential theft.☆52Aug 20, 2025Updated 11 months ago
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆59Sep 20, 2023Updated 2 years ago
- Holds the public Hacking the Cloud CTFs.☆65Feb 28, 2024Updated 2 years ago
- When good OAuth apps go rogue. Documents observed OAuth application tradecraft☆88Apr 7, 2026Updated 4 months ago
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆143May 3, 2026Updated 3 months ago
- Detection tells you a key is real; geiger tells you whether it's dangerous.☆35Updated this week
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Collection of Docker honeypot logs from 2021 - 2024☆36Sep 30, 2024Updated last year
- Determine privileges from cloud credentials via brute-force testing.☆69Jul 25, 2026Updated 2 weeks ago
- An awesome collection of articles, papers, conferences, guides, and tools relating to deception in cybersecurity.☆129Updated this week
- ☆40Aug 2, 2024Updated 2 years ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆2,168Oct 1, 2025Updated 10 months ago
- Create your own vulnerable by design AWS penetration testing playground☆468May 1, 2026Updated 3 months ago
- Exploit for CVE-2024-4883☆11Jul 8, 2024Updated 2 years ago
- A collection of helpful resources related to Cybersecurity and a lot more.☆40Feb 22, 2026Updated 5 months ago
- This repository contains hit lists to use for web application content discovery.☆11May 31, 2017Updated 9 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Dockerfile for AFL++ and helpful other tools☆21May 5, 2020Updated 6 years ago
- A table containing CTF challenge links and their corresponding walkthroughs from different platforms.☆13Oct 23, 2022Updated 3 years ago
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆155Jul 28, 2026Updated last week
- Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.☆584Mar 12, 2026Updated 4 months ago
- moniorg is a tool that leverages crt.sh website to monitor domains of a target☆48Apr 1, 2023Updated 3 years ago
- MCP Attack Surface Detector - Burp plugin to make manual testing of MCP servers easier in Burp Suite☆31Feb 26, 2026Updated 5 months ago
- GitHub Workflows Insights☆47Jun 27, 2026Updated last month