
kics
Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

AWSGoat : A Damn Vulnerable AWS Infrastructure

Automating situational awareness for cloud penetration tests.

Hunt for security weaknesses in Kubernetes clusters

AzureGoat : A Damn Vulnerable Azure Infrastructure

PacBot (Policy as Code Bot)

A tool for quickly evaluating IAM permissions in AWS.

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

Open-source cloud security platform that discovers attack paths, identifies misconfigurations, visualizes IAM access, and provides step-by-step…

Create your own vulnerable by design AWS penetration testing playground

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

GCPGoat : A Damn Vulnerable GCP Infrastructure

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

An AWS IAM policy statement parser and query tool.

Competition Infrastructure Management

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…