
reportly
AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

Modular GCP attack toolkit for offensive research, enabling reconnaissance, authentication manipulation, and exploitation of cloud functions,…

harbor unauthorized detection


Hunt for AI coding artifacts containing secrets.

Scan for open S3 buckets and dump

Find unreferenced AWS S3 buckets which have CloudFront CNAME records pointing to them

Information about Kubernetes CVE-2020-8558, including proof of concept exploit.

Automated S3 bucket security scanner that tests domain lists for publicly accessible buckets with listing permissions, exporting results for cloud…

S3 Account Search

Vendor-neutral NDJSON attack-graph format with node/edge taxonomy, AWS/GCP/Azure mappings, derivation rules, and an exposure DB for offensive…

Strafer: A tool to detect potential infections in Elasticsearch instances

SSL certificate-based reconnaissance engine for discovering AWS cloud assets, including IPs, subdomains, and domains, with active port scanning for…

Mounts AWS resources as a local filesystem for infrastructure exploration, security auditing, and configuration analysis using standard Unix tools…

CVE-2022-46463 harbor公开镜像全自动下载脚本

Scanner for CVE-2022-22948 an Information Disclosure in VMWare vCenter