
LOAD
Lord Of Active Directory - automatic vulnerable active directory on AWS

Lord Of Active Directory - automatic vulnerable active directory on AWS

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

A collection of Azure AD/Entra tools for offensive and defensive security purposes

Boundary enables identity-based access management for dynamic infrastructure.

Java client library for the Kubernetes API, enabling programmatic management of clusters, pods, deployments, and other resources with support for…

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

An open source, self-hosted implementation of the Tailscale control server

DSC resources to simplify administration of certificates on a Windows Server.

Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.

A collection of scripts for assessing Microsoft Azure security

Proof of concept for CVE-2025-12748, a denial-of-service vulnerability in libvirt XML processing that bypasses ACL checks, allowing resource…

Competition Infrastructure Management

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Automating situational awareness for cloud penetration tests.