
CloudScraper
Spider and scrape web targets to discover exposed cloud resources including S3 buckets, Azure Blobs, and DigitalOcean Spaces using regex-based…

Spider and scrape web targets to discover exposed cloud resources including S3 buckets, Azure Blobs, and DigitalOcean Spaces using regex-based…

A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

The source files and tools needed to build the OWASP Cornucopia decks in various languages

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

The globalping probe code that runs on your hardware and connects to the global community network of probes

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

Suite of tools for red teamers and bug hunters to discover ephemeral cloud assets by scanning IP ranges and inspecting SSL certificates for hidden…

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…