
cs-suite
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

A collection of Azure AD/Entra tools for offensive and defensive security purposes

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

ArmourBird CSF - Container Security Framework

Scripts to build Kali cloud images (fork of https://salsa.debian.org/cloud-team/debian-cloud-images)

Ansible playbook to automate mitigation of CVE-2023-46747 (BIG-IP unauthenticated RCE) by applying F5's official script across multiple devices.

PowerShell script to mitigate CVE-2018-12038. The script takes a list of PC as input, gets their BitLocker encryption type remotely, and outputs a…

Naive shell script to verify Meltdown (CVE-2017-5754) patch status of EC2 instances

Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

AWS Least Privilege for Distributed, High-Velocity Deployment

a Damn Vulnerable Serverless Application

A tool to enumerate S3 buckets manually or via certstream

Apache Kafka 4.1.0 (KRaft) with Keycloak OAuth2 authentication using Strimzi - bypasses CVE-2025-27817 URL allowlist restriction