
cloud-sniper
Detection-as-code platform that automates cloud security incident response by correlating artifacts, analyzing IOCs, and orchestrating…

Detection-as-code platform that automates cloud security incident response by correlating artifacts, analyzing IOCs, and orchestrating…

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Portable security rules for the action boundary of AI agents

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

Perform file-based malware scan on your on-prem servers with AWS

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

Discord bot for mitigating the aCropalypse vulnerability (CVE-2023-21036, CVE-2023-28303) by retroactively deleting vulnerable images


Automatic security alert response framework by AWS Serverless Application Model

Virtual Security Operations Center

This is an incident response playbook we created for the Vercel April 2026 compromise

KQL para deteccion de CVE-2025-21333 en Sentinel

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Collects, processes, and visualizes forensic data from cloud and on-premise machine clusters for incident response and digital investigations.

This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…