This repo gives an overview of some GCP metadata API attack and defend patterns
☆79Mar 23, 2020Updated 6 years ago
Alternatives and similar repositories for AttackingAndDefendingTheGCPMetadataAPI
Users that are interested in AttackingAndDefendingTheGCPMetadataAPI are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆28Aug 6, 2020Updated 6 years ago
- These are tools we released with our 2020 defcon/blackhat talk https://www.youtube.com/watch?v=Ml09R38jpok☆175Feb 6, 2025Updated last year
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆102Sep 10, 2019Updated 7 years ago
- POC for CVE-2018-15685☆42Aug 24, 2018Updated 8 years ago
- XXE injection (file disclosure) exploit for Apache OFBiz < 16.11.04☆12Oct 16, 2018Updated 7 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆26Feb 19, 2026Updated 7 months ago
- A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.☆574May 26, 2023Updated 3 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆14Feb 10, 2022Updated 4 years ago
- This lab demonstrates some of the security concerns of a default Kubernetes Engine cluster configuration and the corresponding hardening …☆17Jul 29, 2019Updated 7 years ago
- Detection tells you a key is real; geiger tells you whether it's dangerous.☆36Sep 11, 2026Updated last week
- Salesforce Policy Deviation Checker☆30Sep 30, 2020Updated 5 years ago
- ☆15Feb 26, 2018Updated 8 years ago
- Like the unix tree command but for GCP Org Heirarchy☆27Apr 29, 2021Updated 5 years ago
- Burp Suite Professional extension in Java for Tabnabbing attack☆13May 8, 2018Updated 8 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Slides, Cheatsheet and Resources from our Blackhat EU talk☆39Aug 24, 2020Updated 6 years ago
- Transparently log all data passed into known JavaScript sinks - Sink Logger extension for Burp.☆48Jul 20, 2022Updated 4 years ago
- Tool for CVE-2018-16323☆83Jan 17, 2019Updated 7 years ago
- An auto-scoring capture-the-flag game focusing on TOCTOU vulnerabilities☆21Oct 28, 2020Updated 5 years ago
- Terraform to run Scoutsuite security scan of projects within a Google Cloud Org. Report will be published to a GCS bucket.☆17Jan 5, 2026Updated 8 months ago
- ☆21Nov 13, 2019Updated 6 years ago
- automated penetration toolkit☆12Jul 9, 2016Updated 10 years ago
- Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.☆164Nov 28, 2025Updated 9 months ago
- retrive metadata endpoint data with these one liners.☆41Aug 11, 2020Updated 6 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- differer finds how URLs are parsed by different languages in order to help bug hunters break filters☆63May 3, 2020Updated 6 years ago
- A demo vulnerable application for stealing sensitive information by abusing Google Chrome cache☆20Jan 19, 2020Updated 6 years ago
- ☆46Nov 14, 2020Updated 5 years ago
- PoC for CVE-2021-3129 (Laravel)☆12Oct 9, 2021Updated 4 years ago
- DupeKeyInjector☆133Apr 16, 2022Updated 4 years ago
- Swift code to run a dylib on disk☆16May 9, 2022Updated 4 years ago
- ☆20Dec 1, 2019Updated 6 years ago
- Dynamic DNS Update Bruteforce Tool☆29Feb 8, 2017Updated 9 years ago
- Burp Suite extension to help make Graphql request more readable☆29Dec 7, 2017Updated 8 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Hayat is a script for report and analyze Google Cloud Platform resources.☆82Jan 7, 2020Updated 6 years ago
- The Outlook HTML Leak Test Project☆129May 12, 2018Updated 8 years ago
- ☆33Feb 26, 2015Updated 11 years ago
- Google Compute Engine (GCE) VM takeover via DHCP flood - gain root access by getting SSH keys added by google_guest_agent☆535Jul 30, 2021Updated 5 years ago
- An API client for HashiCorp's Terraform Cloud☆11Jun 7, 2024Updated 2 years ago
- Simple SSH server that serves anonymous git repositories (read-only)☆11Oct 18, 2018Updated 7 years ago
- BURP extension to record every HTTP request send via BURP and create an audit trail log of an assessment.☆66May 2, 2025Updated last year