offensive-terraform / terraform-aws-ebs-snapshot-publicly-exposedLinks
Offensive Terraform module which copies publicly exposed EBS snapshot to us-east-1 region in attacker's AWS account and creates EBS volume from the copied EBS snapshot. After that, the module attaches and mounts the EBS volume to an EC2 instance. Finally, attacker can ssh into an EC2 instance and inspect a mounted volume "/usr/src/hack".
☆15Updated 4 years ago
Alternatives and similar repositories for terraform-aws-ebs-snapshot-publicly-exposed
Users that are interested in terraform-aws-ebs-snapshot-publicly-exposed are comparing it to the libraries listed below
Sorting:
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆134Updated 5 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆76Updated 3 years ago
- 🖇️ STRIDE vs. ASVS equivalence table☆76Updated 10 months ago
- Presentations, training modules, and other education materials from Duo Security's Application Security team.☆74Updated 4 years ago
- A very vulnerable serverless application in AWS Lambda☆96Updated 5 years ago
- Research on the enumeration of IAM permissions without logging to CloudTrail☆61Updated 4 years ago
- GCP GOAT is the vulnerable application for learn the GCP Security☆64Updated last month
- Route53/CloudFront Vulnerability Assessment Utility☆86Updated last year
- Kubernetes Pwnage for all☆57Updated 4 years ago
- Tools to automate AWS Cloud security assessments☆25Updated 5 years ago
- Updated incident response generator for training classes☆44Updated 4 years ago
- ☆14Updated 2 years ago
- Kubernetes Security Testing Guide☆26Updated last year
- Jekyll Files for cloudsecwiki.com☆50Updated 3 years ago
- ☆36Updated 5 years ago
- AppSecPipeline Specification for DevOps automation.☆40Updated 2 years ago
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Updated 2 years ago
- IAMFinder enumerates and finds users and IAM roles in a target AWS account.☆111Updated 4 years ago
- Serverless Workshop☆16Updated 2 years ago
- ☆57Updated 5 years ago
- AWS SSO serverless phishing API.☆32Updated 4 years ago
- Project intended to make Attack Maps part of software development by reducing the time it takes to complete them.☆48Updated 8 years ago
- This repo gives an overview of some GCP metadata API attack and defend patterns☆76Updated 5 years ago
- Pentester-focused Docker registry tool to enumerate and pull images☆111Updated 5 years ago
- The Open Security Summit is focused on the collaboration between, Developers and Application Security☆45Updated last week
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container☆106Updated 6 years ago
- OAuth 2.0 Dynamic Security Scanner☆33Updated 4 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆63Updated 2 years ago
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆78Updated 4 years ago
- ☆66Updated 2 years ago