
nuvola
Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

Curated catalog of AWS resource types that can be publicly exposed, with CLI commands for creating and auditing public access configurations across…

AWS Identity and Access Management Visualizer and Anomaly Finder

Lightweight OpenWRT device management platform for small networks. Centralized configuration, monitoring, and WiFi management for 2–20 devices with…

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

Kubernetes operator for injecting chaos experiments into cloud-native workloads, automating resilience testing and workload hardening through…

A terminal-native remote access suite for SSH, cloud inventories, provider-backed connectors, parallel commands, mux workspaces, file transfer, and…

Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.

Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

Curated dataset of cloud middleware agents installed by AWS, Azure, and GCP, documenting past vulnerabilities, privileges, and attack-surface risks…

Kubernetes driver extension of the Chaos Toolkit probes and actions API

Slides and Codes used for the workshop Red Team Infrastructure Automation

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

An AWS IAM policy statement parser and query tool.

Event-driven AWS security misconfiguration detection framework that monitors multiple accounts in real-time, triggering alerts via Lambda for IAM,…

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

Scans AWS IAM configurations for shadow admins by detecting misconfigured deny policies that fail to restrict user actions on groups, enabling…