offensive-terraform / terraform-aws-ebs-snapshot-publicly-exposed
Offensive Terraform module which copies publicly exposed EBS snapshot to us-east-1 region in attacker's AWS account and creates EBS volume from the copied EBS snapshot. After that, the module attaches and mounts the EBS volume to an EC2 instance. Finally, attacker can ssh into an EC2 instance and inspect a mounted volume "/usr/src/hack".
☆14Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for terraform-aws-ebs-snapshot-publicly-exposed
- AWS SSO serverless phishing API.☆29Updated 3 years ago
- Pivot into private VPC networks using a VPN connection☆41Updated 5 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆74Updated 2 years ago
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆133Updated 4 years ago
- Research on the enumeration of IAM permissions without logging to CloudTrail☆60Updated 3 years ago
- Scripts and tools for AWS Pentest☆51Updated 4 years ago
- Jekyll Files for cloudsecwiki.com☆49Updated 3 years ago
- Kubernetes Security Testing Guide☆26Updated 6 months ago
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 4 years ago
- Offensive Terraform module which creates EC2 instance and reverse shell from an EC2 instance to attacker machine.☆17Updated 4 years ago
- Route53/CloudFront Vulnerability Assessment Utility☆84Updated last year
- This is a set of tips and reminders for pentesting processes and scripts/programs. Initially for personal use, but if anyone else finds t…☆52Updated 4 years ago
- This repository contains links to awesome security articles.☆36Updated 2 months ago
- ☆58Updated last year
- A simple file-based scanner to look for potential AWS access and secret keys in files☆89Updated 7 months ago
- A combined list of helpful awscli commands from Scott Piper's flaws.cloud exercise as well as from Beau Bullock's Breaching the Cloud Tra…☆18Updated 3 years ago
- Proof-of-concept CORS exploitation tool.☆34Updated 5 years ago
- ☆31Updated 4 years ago
- AWS Extender CLI is a command-line script to test S3 buckets as well as Google Storage buckets and Azure Storage containers for common mi…☆81Updated 4 years ago
- A tool to enumerate S3 buckets manually or via certstream☆80Updated last year
- Presentations, training modules, and other education materials from Duo Security's Application Security team.☆71Updated 3 years ago
- Serverless Workshop☆16Updated last year
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆76Updated 3 years ago
- AWS Security Checks☆36Updated 6 years ago
- An AWS Lambda vulnerable application written in flask.☆48Updated 7 years ago
- Kubernetes Pwnage for all☆54Updated 3 years ago
- A public cloud security knowledgebase - https://www.secwiki.cloud/☆48Updated 8 months ago
- ☆125Updated 3 months ago
- 🖇️ STRIDE vs. ASVS equivalence table☆75Updated 2 months ago