
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

automated password spraying tool

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Open Source Cloud Native Application Protection Platform (CNAPP)

A self-hosted Fuzzing-As-A-Service platform

A security-focused library OS supporting kernel- and user-mode execution

Generates least-privilege AWS IAM policies based on resource ARNs and access levels, automating secure policy creation for cloud infrastructure.

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

PowerShell framework to assess Azure security

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

AzureGoat : A Damn Vulnerable Azure Infrastructure

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

RedCloudOS is a Cloud Adversary Simulation Operating System for Red Teams to assess the Cloud Security of Leading Cloud Service Providers (CSPs)

A PowerShell script that automates the security assessment of Microsoft 365 environments.