pushsecurity / saas-attacksLinks
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
☆1,389Updated 5 months ago
Alternatives and similar repositories for saas-attacks
Users that are interested in saas-attacks are comparing it to the libraries listed below
Sorting:
- AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE…☆1,200Updated last month
- A web application that assists network defenders, analysts, and researchers in the process of mapping adversary behaviors to the MITRE AT…☆1,203Updated last week
- Automating situational awareness for cloud penetration tests.☆2,254Updated last month
- Incident Response Methodologies 2022☆1,088Updated 8 months ago
- FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is de…☆819Updated 9 months ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,785Updated 2 months ago
- AzureGoat : A Damn Vulnerable Azure Infrastructure☆901Updated last year
- Open source templates you can use to bootstrap your security programs☆881Updated 6 months ago
- BlueHound - pinpoint the security issues that actually matter☆754Updated 2 years ago
- A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigatin…☆471Updated 6 months ago
- A collection of resources, tools and more for penetration testing and securing Microsofts cloud platform Azure.☆1,167Updated last year
- Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation o…☆1,094Updated 3 weeks ago
- Granular, Actionable Adversary Emulation for the Cloud☆2,211Updated this week
- You didn't think I'd go and leave the blue team out, right?☆1,706Updated last week
- A curated list of annual cyber security reports☆892Updated this week
- Azure and AWS Attacks☆1,107Updated 3 years ago
- Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study by Xena Olsen.☆669Updated 2 years ago
- Streamline vulnerability patching with CVSS, EPSS, and CISA's Known Exploited Vulnerabilities. Prioritize actions based on real-time thre…☆680Updated 2 months ago
- AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover se…☆1,461Updated 9 months ago
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆1,945Updated 6 months ago
- My cheatsheet notes to pentest AWS infrastructure☆696Updated 3 years ago
- Purple Team Exercise Framework☆752Updated last year
- This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and …☆2,432Updated last month
- A Post-exploitation Toolset for Interacting with the Microsoft Graph API☆1,234Updated 4 months ago
- This project aims to compare and evaluate the telemetry of various EDR products.☆1,896Updated 2 weeks ago
- Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.☆738Updated this week
- GitHub Actions Pipeline Enumeration and Attack Tool☆717Updated 2 months ago
- Resources for Application Security including Web, API, Android, iOS and Thick Client☆686Updated 2 years ago
- GCPGoat : A Damn Vulnerable GCP Infrastructure☆420Updated last year
- 💀 Don't fear the Reaper 👻☆705Updated 3 weeks ago