
Thunderstorm
A collector and derivation engine. It maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a…

A collector and derivation engine. It maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a…

A tool to enumerate S3 buckets manually or via certstream

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

Finds internet-exposed resources in an AWS account

An open source real-time network topology and protocols analyzer

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares

Identify IP addresses owned by public cloud providers

simply nodes and graphs

S3 Account Search

Cross-cloud S3-compatible object storage CLI to list, export, and download buckets across AWS, Aliyun, Tencent, Huawei and more, with anonymous…

Acquires the EBS disks of an AWS AMI you can launch, streaming snapshots via EBS direct APIs to a private S3 bucket with sha256 manifests and…

Red team operations management platform automating infrastructure deployment, C2 setup, phishing campaigns, and reconnaissance with integrated tool…

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…