
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

An egress firewall for untrusted workloads.

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…


A collection of awesome security hardening guides, tools and other resources

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

List of regex for scraping secret API keys and juicy information.

Tooling for assessing an Azure AD tenant state and configuration

Summary of Cyber Security interview questions I have been through, hope this helps

Purple Team Exercise Framework

SSRF (Server Side Request Forgery) testing resources

A tool for pointesters to find candies in SharePoint

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information


This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.