
BloodHound
Six Degrees of Domain Admin
Tools for managing user identities, authentication, authorization, and access controls within systems and networks.

Six Degrees of Domain Admin

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Audits Azure AD and Exchange Online configurations for hard-to-find permissions, federation trusts, mail forwarding rules, and delegated access to…

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

Scans AWS IAM configurations for shadow admins by detecting misconfigured deny policies that fail to restrict user actions on groups, enabling…

A tool to scan Kubernetes cluster for risky permissions

Lightweight edge HTTP(S) server and reverse proxy with automatic SSL, Docker/Consul discovery, per-route authentication, rate limiting, and…

Declarative authorization library with a DSL for writing policy rules, conditions, and caching. Enables scalable, DRY permission management for Ruby…

Reconciliation audit for Alliance Auth's Discord integration: finds guild members holding AA-managed roles that Auth never granted and strips or…

A flexible, composable authorization framework for Kit (inspired by Action Policy)

OAuth 2.0 client library for Kit applications supporting authorization code, PKCE, client credentials, and refresh token flows with built-in provider…

Infrastructure cloud modulaire, redondante et 100% souveraine pour s'affranchir des GAFAM. Guides techniques, architecture Zero-Trust et chiffrement…

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™


Keep it secret, keep it safe

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…