offensive-actions / terraform-provider-statefile-rceView external linksLinks
This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.
☆61Jan 25, 2025Updated last year
Alternatives and similar repositories for terraform-provider-statefile-rce
Users that are interested in terraform-provider-statefile-rce are comparing it to the libraries listed below
Sorting:
- ☆39Aug 2, 2024Updated last year
- Semgrep-based Policy Controller for Kubernetes☆47Apr 4, 2025Updated 10 months ago
- When good OAuth apps go rogue. Documents observed OAuth application tradecraft☆84Jan 30, 2026Updated 2 weeks ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆48Sep 20, 2024Updated last year
- A CLI tool (and library) written in Go to simplify the process of retrieving IP addresses from infrastructure hosted on Google Cloud Plat…☆11Nov 20, 2025Updated 2 months ago
- Official code for the paper entitled "Toward Intelligent and Secure Cloud: Large Language Model Empowered Proactive Defense"☆15Apr 10, 2025Updated 10 months ago
- An IAM Simulator that outputs detailed explains of how a request was evaluated.☆97Updated this week
- Unauthenticated enumeration of AWS IAM Roles.☆26Sep 7, 2025Updated 5 months ago
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆40Aug 29, 2024Updated last year
- Pentester-focused Docker registry tool to enumerate and pull images☆36Oct 19, 2025Updated 3 months ago
- AWS honey token manager☆89Aug 1, 2024Updated last year
- ☆192Apr 16, 2025Updated 10 months ago
- Expand IAM Actions with Wildcards☆34Updated this week
- Utility for downloading and mounting EBS snapshots using the EBS Direct API's☆91Mar 17, 2025Updated 11 months ago
- A tool to audit Erlang & Elixir dependencies, to make sure your ✨ gleam projects really sparkle!☆23Jan 5, 2026Updated last month
- Open-source best practices for protecting a secure, sensible cloud platform☆129Oct 25, 2024Updated last year
- ☆42Nov 13, 2025Updated 3 months ago
- A web CTF for training developers in bug hunting and secure coding!☆100Jan 12, 2025Updated last year
- Hijack a slack bot to phish your way in☆57Jul 17, 2025Updated 7 months ago
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments☆141Jan 2, 2025Updated last year
- Tricard - Malware Sandbox Fingerprinting☆23Dec 11, 2023Updated 2 years ago
- ☆36Apr 29, 2025Updated 9 months ago
- AWS IAM Username Enumerator and Password Spraying Tool in Python3☆87Dec 7, 2025Updated 2 months ago
- A fork of the Go language with some tweaks☆55Jan 29, 2025Updated last year
- KYE: Know Your Enemies - Check external access on your AWS account☆129Apr 25, 2025Updated 9 months ago
- ☆46Nov 7, 2024Updated last year
- Halberd : Multi-Cloud Agentic Attack Tool☆334Jan 12, 2026Updated last month
- Supply-Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆214Feb 10, 2026Updated last week
- Local CLI tool for browser extension risk analysis☆27Apr 11, 2025Updated 10 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆42Dec 12, 2024Updated last year
- RequestShield is a 100% Free and OpenSource tool designed to analyze HTTP access.logs and identify suspicious HTTP requests and potential…☆106Dec 2, 2024Updated last year
- ☆228Jan 29, 2026Updated 2 weeks ago
- ☆29Dec 26, 2025Updated last month
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalation☆109Feb 16, 2024Updated 2 years ago
- A Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakes☆43Nov 28, 2025Updated 2 months ago
- ☆94Dec 15, 2025Updated 2 months ago
- Burp Suite extension for testing Passkey systems.☆75Apr 1, 2025Updated 10 months ago
- vBrowser is a secure, containerized browser platform designed for covert web investigations. Originally created to support deep and dark …☆20Jan 11, 2026Updated last month
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆35Jan 25, 2026Updated 3 weeks ago