sebastian-mora / AWS-Loot
Pull secrets from an AWS environment
☆70Updated 5 years ago
Alternatives and similar repositories for AWS-Loot:
Users that are interested in AWS-Loot are comparing it to the libraries listed below
- EC2StepShell is an AWS post-exploitation tool for getting high privileges reverse shells in public or private EC2 instances.☆63Updated 7 months ago
- Determine privileges from cloud credentials via brute-force testing.☆67Updated 8 months ago
- Enumerate AWS permissions and resources.☆68Updated 2 years ago
- ☆55Updated last year
- AWS Security Tool☆30Updated last year
- ☆57Updated last year
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.☆31Updated 3 years ago
- AWS SSO serverless phishing API.☆32Updated 3 years ago
- Objectify-s3 is a tool that recursively checks AWS S3 buckets and objects for misconfigured permissions.☆15Updated 8 months ago
- ☆90Updated 3 years ago
- Offensive Terraform Website☆44Updated 4 years ago
- ☆126Updated 9 months ago
- WAF bypass PoC☆47Updated last year
- Tool to check the CloudTrail configuration and the services where trails are sent, to detect potential attacks to CloudTrail logging.☆13Updated 10 months ago
- ☆35Updated 3 weeks ago
- Jenkins Security Research or Hacking Jenkins ;)☆11Updated 4 months ago
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated last year
- A toolset to juggle AWS roles for persistent access☆56Updated 8 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆40Updated last year
- A small library to alter AWS API requests; Used for fuzzing research☆22Updated last year
- A multi-cloud DNS record scanner that aims to help cybersecurity/IT analysts identify dangling CNAME records in their cloud DNS services …☆49Updated 2 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆76Updated 3 years ago
- HazProne is a Cloud Pentesting Framework that emulates close to Real-World Scenarios by deploying Vulnerable-By-Demand AWS resources enab…☆39Updated 2 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Updated 3 years ago
- ☆17Updated 2 years ago
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆106Updated 5 months ago
- A steampipe plugin to query projectdiscovery.io tools.☆26Updated 9 months ago
- ☆46Updated 10 months ago
- This repository mainly focuses on various techniques, tools, frameworks and approach to perform offensive exploitation of AWS infrastruct…☆11Updated 5 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆47Updated last year