
discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Daily updated SSL certificate dataset for AWS EC2 and GCP IP ranges, enabling subdomain enumeration, origin IP discovery, and cloud asset…

Multi-cloud asset enumeration tool that aggregates resources from AWS, GCP, Azure, and 20+ providers with keyless auth, filters, and multiple output…

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Azure APIM-based password spraying toolkit with IP rotation for authorized red team assessments. Supports spray and validate modes with configurable…

Determine privileges from cloud credentials via brute-force testing.

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Scan for misconfigured S3 buckets across S3-compatible APIs!

Identify privilege escalation paths within and across different clouds

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

Fast and stealthy Amazon S3 bucket enumeration tool for pentesters.

CVE-2026-55726 disclosure detailing a publicly listable Azure Blob Storage container exposing Gardyn IoT device logs, including SSIDs, firmware…

CVE-2026-13768 advisory detailing critical Azure IoT Hub iothubowner credential abuse enabling fleet-wide device enumeration, remote code execution…

Automated reconnaissance tool that performs subdomain enumeration, vulnerability scanning, OSINT, port scanning, and web analysis to map attack…

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…