
stratus-red-team
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

A collection of scripts for assessing Microsoft Azure security

Automating situational awareness for cloud penetration tests.

A collection of AWS penetration testing junk

A tool for quickly evaluating IAM permissions in AWS.

A tool to extract the IdP cert from vCenter backups and log in as Administrator

AWS Identity and Access Management Visualizer and Anomaly Finder

An AWS IAM policy statement parser and query tool.

Competition Infrastructure Management

An AI-powered tool for discovering privilege escalation opportunities in AWS IAM configurations.

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

WorldFirst (Public) Docker API Exploit - My security researches involving Docker and Openshift

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

Exploit for Linux kernel CVE-2026-31431 causing page cache corruption via authencesn AEAD manipulation, targeting privilege escalation in containers…

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)