opendevsecops / guide-aws-hacking
This is an offensive guide to securing AWS infrastructures. The hope is that by knowing how to take advantage of various types of AWS weaknesses you will be verse enough to provide the correct countermeasures.
☆169Updated 5 years ago
Alternatives and similar repositories for guide-aws-hacking:
Users that are interested in guide-aws-hacking are comparing it to the libraries listed below
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆135Updated 4 years ago
- Damn Vulnerable Cloud Application☆190Updated 6 years ago
- AWS S3 Bucket/Object Finder☆118Updated 3 years ago
- A simple file-based scanner to look for potential AWS access and secret keys in files☆89Updated 10 months ago
- Find cloud assets that no one wants exposed 🔎 ☁️☆334Updated 4 years ago
- A tool geared towards pentesting APIs using OpenAPI definitions.☆172Updated 2 years ago
- Hands-On AWS Penetration Testing with Kali Linux published by Packt☆130Updated 2 years ago
- How to prepare for OSCP complete guide☆128Updated 5 years ago
- Search exposed EBS volumes for secrets☆291Updated last year
- This repository will contain all trainings and tutorials I have done/read to prepare for OSWE / AWAE.☆235Updated 5 years ago
- Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).☆123Updated last year
- Cloud-related research releases from the Rhino Security Labs team.☆377Updated 4 years ago
- Some good resources for getting started with application security☆141Updated 3 years ago
- A tool to enumerate S3 buckets manually or via certstream☆80Updated last year
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆99Updated last year
- Fast and stealthy Amazon S3 bucket enumeration tool for pentesters.☆240Updated this week
- ☆273Updated 3 years ago
- ☆238Updated 7 months ago
- A place to store my own wordlists, and link to others that are useful☆106Updated last year
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!☆119Updated 2 years ago
- Resources to learn cloud environment and pentesting the same, contains AWS, Azure, Google Cloud☆50Updated 2 years ago
- Route53/CloudFront Vulnerability Assessment Utility☆84Updated last year
- Dr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful information! It's yo…☆215Updated 5 years ago
- Pentesting/Bugbounty Dockerfiles.☆175Updated 3 years ago
- Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities☆135Updated 2 years ago
- ☆76Updated 2 years ago
- Fetch the details of assets hosted on AWS.☆86Updated last year
- ☆71Updated 4 years ago
- A collection of response templates for invalid bug bounty reports.☆90Updated 6 years ago
- Amazon bucket brute force tool☆95Updated 11 years ago