jordanpotti / guardduty-opsec
Opsec considerations for each AWS GuardDuty finding type.
☆22Updated 4 years ago
Alternatives and similar repositories for guardduty-opsec:
Users that are interested in guardduty-opsec are comparing it to the libraries listed below
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆76Updated 3 years ago
- Research on the enumeration of IAM permissions without logging to CloudTrail☆60Updated 3 years ago
- ☆134Updated last year
- This is a custom SSM agent which is sorta functional☆17Updated 3 years ago
- Collection of Slides From My Conference Talks☆20Updated 2 years ago
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated last year
- Determine privileges from cloud credentials via brute-force testing.☆67Updated 7 months ago
- ☆15Updated 2 years ago
- A combined list of helpful awscli commands from Scott Piper's flaws.cloud exercise as well as from Beau Bullock's Breaching the Cloud Tra…☆19Updated 4 years ago
- Slackhound allows red and blue teams to perform fast reconnaissance on Slack workspaces/organizations to quickly search user profiles, lo…☆78Updated last year
- An AWS Pentesting tool that lets you use one-liner commands to backdoor an AWS account's resources with a rogue AWS account - or share th…☆11Updated 4 years ago
- AWS SSO serverless phishing API.☆32Updated 3 years ago
- Jekyll Files for cloudsecwiki.com☆50Updated 3 years ago
- ☆58Updated last year
- This script is a multi-threaded Okta password sprayer.☆70Updated last year
- Burp Extension for AWS Signing☆87Updated 2 months ago
- An AWS Lambda vulnerable application written in flask.☆48Updated 7 years ago
- Payload designed for targeting Jamf enrolled devices.☆37Updated last year
- Ansible playbooks for instrumenting a Red Team environment with RedElk☆47Updated 4 years ago
- Next Generation Phishing Tool For Internal / Red Teams☆35Updated 5 years ago
- Terraform script to deploy AD-based environment on Azure☆41Updated last year
- A collection of Neo4j/BloodHound queries to collect interesting information.☆45Updated 2 years ago
- Terraform resources for building HTTP, DNS, phishing, and mail server red team infrastructure☆94Updated 5 years ago
- List of Red Team Resources☆17Updated 4 years ago
- Visualize your Terraform files☆34Updated 4 years ago
- Automated deployment and configuration of a Mythic server using Terraform and Ansible☆9Updated last year
- Electron based screenshot scanner☆67Updated 2 years ago
- Hide from the InstanceCredentialExfiltration GuardDuty finding by using VPC Endpoints☆113Updated last year
- GCP cloud security CTF☆44Updated last year
- Blogpost series showcasing interesting cloud - web app security bugs☆47Updated last year