nemo-wq / privilege_escalationLinks
Lab exercises to practice privilege escalation scenarios in AWS IAM. These exercises and the slides go through the basics behind AWS IAM, common weaknesses in AWS deployments, specific to IAM, and how to exploit them manually. This was run as a workshop at BruCon 2019.
☆16Updated 6 years ago
Alternatives and similar repositories for privilege_escalation
Users that are interested in privilege_escalation are comparing it to the libraries listed below
Sorting:
- Scripts and tools for AWS Pentest☆53Updated 5 years ago
- Pivot into private VPC networks using a VPN connection☆43Updated 6 years ago
- ☆29Updated 9 years ago
- An AWS Lambda vulnerable application written in flask.☆49Updated 8 years ago
- ☆18Updated 8 years ago
- Kubernetes Scanner☆40Updated 3 years ago
- This is a Burpsuite plugin built to enable you to import your directory bruteforcing results into burp for easy viewing later. This is an…☆36Updated 2 years ago
- A collection of scripts used to interact with the Burp Rest API☆56Updated 7 years ago
- A collection of OSCE preparation resources.☆24Updated 6 years ago
- Notes as I learn basic AWS penetration testing☆67Updated 6 years ago
- A collection of slides, videos, and proof-of-concept scripts from various Rhino presentations.☆38Updated 7 years ago
- Alphanumeric Encoder☆25Updated 7 years ago
- A Burp Suite content discovery plugin that add the smart into the Buster!☆32Updated 8 years ago
- This is a set of tips and reminders for pentesting processes and scripts/programs. Initially for personal use, but if anyone else finds t…☆52Updated 5 years ago
- Burp Extension for AWS Signing☆90Updated last year
- An enumeration and exploitation toolkit using RFC calls to SAP☆40Updated 6 years ago
- Repository for all the workshop content delivered at nullcon X on 1st of March 2019☆80Updated 6 years ago
- ☆21Updated 6 years ago
- API testing tool written with Python☆56Updated 9 years ago
- AWS S3 Bucket/Object Finder☆25Updated 8 years ago
- Slides of the talk on Injection attacks in apps with NoSQL Backends, given at null OWASP Bangalore monthly meet on 27th April 2019☆23Updated 6 years ago
- Yet another open S3 bucket finder☆20Updated 7 years ago
- Purpose of this repository is to help all the beginner and experienced professionals to understand,learn and share new tricks for the com…☆32Updated 7 years ago
- Terraform configuration to build a Burp Private Collaborator Server☆25Updated 8 years ago
- A Burp Extender plugin that will allow you to tamper with requests containing compressed, serialized java objects.☆24Updated 6 years ago
- A Pythonic wrapper to MassDNS☆24Updated 7 years ago
- This repo will contain slides and information from the Attacking Active Directory Hacking Series talks presented at SecKC.☆32Updated last year
- Sparty - MS Sharepoint and Frontpage Auditing Tool☆32Updated 11 years ago
- ☆24Updated 3 months ago
- This burpsuite extender provides a solution on testing Enterprise applications that involve security Authorization tokens into every HTTP…☆47Updated 6 years ago