
Maestro
Abusing Azure services over C2

Abusing Azure services over C2

AzureRT - A Powershell module implementing various Azure Red Team tactics

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Azure Post Exploitation Framework

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

Cloud Exploit Framework

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

An AI-powered tool for discovering privilege escalation opportunities in AWS IAM configurations.

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Python-based framework for generating Golden SAML tokens, Kerberos tickets, and Azure Access Tokens to exploit federated identity systems and…

An AWS IAM policy statement parser and query tool.

PowerShell module for post-breach Azure red teaming, automating token extraction, resource enumeration, and lateral movement within managed identity…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.