Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.
☆77Mar 4, 2022Updated 4 years ago
Alternatives and similar repositories for s3_objects_check
Users that are interested in s3_objects_check are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Simple python script to check against hypothetical JWT vulnerability.☆51Nov 29, 2020Updated 5 years ago
- take a list of resolved subdomains and output any corresponding CNAMES en masse.☆18Jan 29, 2026Updated 5 months ago
- Salesforce Policy Deviation Checker☆30Sep 30, 2020Updated 5 years ago
- FestIn - Open S3 Bucket Scanner☆233Dec 4, 2020Updated 5 years ago
- A bash script that automates the scanning of a target network for HTTP resources through XXE☆38Dec 2, 2020Updated 5 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- IAMFinder enumerates and finds users and IAM roles in a target AWS account.☆109Nov 19, 2020Updated 5 years ago
- All-in-One WP Migration-Backup-Finder☆16Nov 5, 2025Updated 8 months ago
- ☆16May 3, 2021Updated 5 years ago
- rpCheckup is an AWS resource policy security checkup tool that identifies public, external account access, intra-org account access, …☆164Apr 22, 2021Updated 5 years ago
- Burp Extension for copying requests safely. It redacts headers like Cookie, Authorization and X-CSRF-Token for now. More support can be a…☆19May 17, 2020Updated 6 years ago
- sgCheckup generates nmap output based on scanning your AWS Security Groups for unexpected open ports.☆80Sep 2, 2021Updated 4 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities☆48Jan 11, 2023Updated 3 years ago
- ☆11Jul 28, 2020Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Search exposed EBS volumes for secrets☆307Apr 24, 2023Updated 3 years ago
- CVE-2020-25223☆11Sep 13, 2021Updated 4 years ago
- ☆33Aug 14, 2020Updated 5 years ago
- ☆24Aug 9, 2022Updated 3 years ago
- Exactly what it sounds like, which is something rad☆22Oct 12, 2022Updated 3 years ago
- Monitors Github for leaked secrets☆207Oct 25, 2024Updated last year
- ☆84Dec 5, 2019Updated 6 years ago
- Scripts to quickly fix security and compliance issues☆28Mar 10, 2026Updated 4 months ago
- Unauthenticated enumeration of AWS, Azure, and GCP Principals☆292Jun 10, 2026Updated last month
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Finds Directory Listings or open S3 buckets from a list of URLs☆52Dec 1, 2021Updated 4 years ago
- S3 bucket finder from html,js and bucket misconfiguration testing tool☆34Feb 10, 2020Updated 6 years ago
- Easy discovery of assets☆13Jun 22, 2022Updated 4 years ago
- An easy to navigate list of unicode characters that have risky transformations 💥☆24Mar 22, 2022Updated 4 years ago
- A simple Toolkit to BF and decrypt Windows EntraId CacheData☆20Jun 20, 2024Updated 2 years ago
- ☆159Jul 8, 2023Updated 3 years ago
- A MITRE ATT&CK Navigator export for AWS GuardDuty Findings☆138Jul 23, 2021Updated 4 years ago
- A tool for testing subdomain takeover possibilities at a mass scale.☆50May 23, 2021Updated 5 years ago
- A centralized source of all AWS IAM privilege escalation methods released by Rhino Security Labs.☆930Jul 25, 2019Updated 6 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- The original AWS security enforcer™☆61Mar 6, 2019Updated 7 years ago
- Tool to spray AWS Console IAM Logins☆36Jun 15, 2022Updated 4 years ago
- Research on the enumeration of IAM permissions without logging to CloudTrail☆60Jun 11, 2021Updated 5 years ago
- Tool to extract & validate google fcm server keys from apks☆31Jan 20, 2021Updated 5 years ago
- Takes a list of domains as the input, checks if they have a security.txt, outputs the results.☆16May 15, 2020Updated 6 years ago
- Dashboard/API + DNS/HTTP Servers to identify Out of Band Resolution in Payloads☆38Jun 10, 2021Updated 5 years ago
- Automated Attack Simulation in the Cloud, complete with detection use cases.☆618Nov 28, 2024Updated last year