
iam-vulnerable
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

barq: The AWS Cloud Post Exploitation framework!

AMIRA: Automated Malware Incident Response & Analysis

Information about Kubernetes CVE-2020-8558, including proof of concept exploit.

This is an incident response playbook we created for the Vercel April 2026 compromise

flask heroku C2 redirector template

Google App Engine Flask C2 redirector

Proof of concept about the privilege escalation flaw identified in Google's Osconfig

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

HashiCorp Consul exploit with python. (CVE-2021-41805)

OPA Gatekeeper-based policy templates to mitigate CVE-2020-8554 by restricting Kubernetes Service external IPs to an allow list, preventing traffic…

CVE-2024-10220 Test repo

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

Ansible role for workaround for CVE-2017-2636 (Red Hat) - https://access.redhat.com/security/cve/CVE-2017-2636

CVE-2021-44228 log4j mitigation using aws wafv2 with ansible

automated password spraying tool

Stage two containers

Mitigates CVE-2016-5195 aka DirtyCOW