
hacktricks-cloud
Community-driven knowledge base for pentesting cloud environments and CI/CD pipelines: attack techniques, enumeration, privilege escalation, and…

Community-driven knowledge base for pentesting cloud environments and CI/CD pipelines: attack techniques, enumeration, privilege escalation, and…

Pull Request-like Review/Approval flow for database queries. For compliant but smooth Engineering access to production.

A reverse proxy like nginx, built on pingora, simple and efficient.

Your agent is a security risk, so treat it like one. yoloAI does AI agent sandboxing right.

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Kubernetes Lab for CVE-2022-42889

My cheatsheet notes to pentest AWS infrastructure

Pentester-focused Docker registry tool to enumerate and pull images