
s3crets_scanner
Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

A tool to hunt for publicly accessible DigitalOcean Spaces

A tool to enumerate S3 buckets manually or via certstream

A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Use this tool to prioritize cluster patching for the recent VMware advisory VMSA-2018-0027 related to CVE-2018-6981 and CVE-2018-6982.

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

AWS Testing and Reporting Management Tool

An AWS IAM policy statement parser and query tool.

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

Discover resources created in an AWS account.

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Extensible Azure Security Tool - Documentation

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…