pushsecurity / saas-attacks
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
☆1,192Updated this week
Related projects ⓘ
Alternatives and complementary repositories for saas-attacks
- FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is de…☆741Updated 2 months ago
- Automating situational awareness for cloud penetration tests.☆1,959Updated last month
- Azure and AWS Attacks☆1,048Updated last year
- Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation o…☆852Updated 2 months ago
- My cheatsheet notes to pentest AWS infrastructure☆658Updated 2 years ago
- Incident Response Methodologies 2022☆978Updated 9 months ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,436Updated 3 weeks ago
- AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover se…☆1,172Updated this week
- A collection of resources, tools and more for penetration testing and securing Microsofts cloud platform Azure.☆1,014Updated 10 months ago
- Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study by Xena Olsen.☆641Updated last year
- A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automat…☆1,492Updated this week
- A resource containing all the tools each ransomware gangs uses☆763Updated 2 weeks ago
- AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE…☆973Updated last month
- BlueHound - pinpoint the security issues that actually matter☆717Updated last year
- Websec interview questions by tib3rius answered☆304Updated last year
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆1,732Updated this week
- Send phishing messages and attachments to Microsoft Teams users☆1,032Updated 5 months ago
- The TTPForge is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).☆342Updated this week
- A collection of sources of documentation, as well as field best practices, to build/run a SOC☆1,246Updated this week
- Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.☆634Updated last month
- This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple…☆567Updated 4 months ago
- practical toolkit for cybersecurity and IT professionals. It features a detailed Linux cheatsheet for incident response☆380Updated 10 months ago
- AzureGoat : A Damn Vulnerable Azure Infrastructure☆789Updated 3 weeks ago
- A Post-exploitation Toolset for Interacting with the Microsoft Graph API☆955Updated 2 weeks ago
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆1,751Updated 3 weeks ago
- Purple Team Exercise Framework☆626Updated 10 months ago
- Streamline vulnerability patching with CVSS, EPSS, and CISA's Known Exploited Vulnerabilities. Prioritize actions based on real-time thre…☆534Updated 2 weeks ago
- A web application that assists network defenders, analysts, and researchers in the process of mapping adversary behaviors to the MITRE AT…☆1,129Updated 3 weeks ago
- Awesome Security lists for SOC/CERT/CTI☆715Updated this week
- Pentesting cheatsheet with all the commands I learned during my learning journey. Will try to to keep it up-to-date.☆1,262Updated this week