
CloudHunter
Find unreferenced AWS S3 buckets which have CloudFront CNAME records pointing to them

Find unreferenced AWS S3 buckets which have CloudFront CNAME records pointing to them

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

List of regex for scraping secret API keys and juicy information.

A tool for pointesters to find candies in SharePoint

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

AAD related enumeration in Nim

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

Abusing Azure services over C2

onedrive user enumeration - pentest tool to enumerate valid o365 users

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Authenticated SSRF in Grafana

Prommetrix can obtain relevant information from the instances of 'Node Exporter' executed by 'Prometheus'.

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Appspec YML and YAML leaks

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

MinIO敏感信息泄露漏洞批量扫描poc&exp