
iam-vulnerable
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

Create On Demand Disposable OpenVPN Endpoints on AWS.

Secure agents in seconds with permissions enforced at runtime.

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Create your own vulnerable by design AWS penetration testing playground

Batch exploit script for CVE-2019-16097, targeting Harbor container registry to create unauthorized admin accounts via crafted API requests.

Cloud native secrets management for developers - never leave your command line for secrets.

Security risk analysis for Kubernetes resources

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

cMCP: Confidential MCP Gateway. Hardware-attested policy enforcement for MCP tool calls.

A collection of manifests that will create pods with elevated privileges.

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

Blue Team detection lab created with Terraform and Ansible in Azure.

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

TunnelX is a lightweight ingress tunneling tool designed to create a secure SOCKS5 proxy server for routing network traffic.