
SnaffPoint
A tool for pointesters to find candies in SharePoint

A tool for pointesters to find candies in SharePoint

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

🏰 A Python script for AWS S3 bucket enumeration.

Azure mindmap for penetration tests

Collection of offensive tools targeting Microsoft Azure

A high-performance, eBPF-based network traffic analyzer written in Rust.

A collection of scripts, and tips and tricks for hacking k8s clusters and containers.

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform

A Azure Exploitation Toolkit for Red Team & Pentesters

A collector and derivation engine. It maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a…

Go toolkit for authorized Azure security assessments: enumerates subscriptions and resources, audits misconfigurations, and attacks public Blob…

AI runtime inventory: discover shadow AI, trace LLM calls

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

Authorized cloud adversary simulation and validation toolkit

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.