
CVE-2026-64849
Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

A community‑driven cybersecurity knowledge base with 400+ notes, mind‑maps, and cheat‑sheets – built from first principles. Ideal for students, SOC…

Scripts to build Kali cloud images (fork of https://salsa.debian.org/cloud-team/debian-cloud-images)



Summary of Cyber Security interview questions I have been through, hope this helps

A tool for pointesters to find candies in SharePoint

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information


My cheatsheet notes to pentest AWS infrastructure

Generates and maintains Azure Sentinel parser for Sysmon events, normalizing all Windows endpoint telemetry into a searchable log schema via…

Automation to assess the state of your M365 tenant against CISA's baselines

This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.

A list of awesome penetration testing tools and resources.

Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.

Collection of tools to use with Azure Applications