
nuvola
Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.

A tool to hunt for publicly accessible DigitalOcean Spaces

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

WorldFirst (Public) Docker API Exploit - My security researches involving Docker and Openshift

we are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in…

Azure CLI extension for Cirro collection

OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML…

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

Cisco SD-WAN Exposure & Potential Vulnerability Scanner (Passive Fingerprinting) 2026

Use this tool to prioritize cluster patching for the recent VMware advisory VMSA-2018-0027 related to CVE-2018-6981 and CVE-2018-6982.

Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

A collection of AWS penetration testing junk

Attack Surface Management since before Attack Surface Management was a thing

Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services

AWS Identity and Access Management Visualizer and Anomaly Finder