
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

The Open-Source AWS Cyber Range


A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.

AI-powered offensive security testing using autonomous agents, directly in your terminal.

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

A container analysis and exploitation tool for pentesters and engineers.

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

barq: The AWS Cloud Post Exploitation framework!

A tool that implements the Golden SAML attack

Proof-of-concept exploit for CVE-2018-1002105 targeting Kubernetes API server. Supports authenticated and unauthenticated privilege escalation to…

Autonomous red-team engagement platform with MITRE ATT&CK module orchestration, DAG attack-path solving, OPSEC controls, encrypted credential vault,…

AWS Identity and Access Management Visualizer and Anomaly Finder

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

A collection of scripts, and tips and tricks for hacking k8s clusters and containers.


Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus