
restler-fuzzer
RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

A tool for checking if MFA is enabled on multiple Microsoft Services

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Intentionally vulnerable Terraform infrastructure for learning cloud misconfiguration detection and DevSecOps practices across AWS, Azure, and GCP.

Open source solutions for SOC2, GDPR, and ISO27001

Generates least-privilege AWS IAM policies based on resource ARNs and access levels, automating secure policy creation for cloud infrastructure.

Cloud native secrets management for developers - never leave your command line for secrets.

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Security Tool to Look For Interesting Files in S3 Buckets

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

Cloudlist is a tool for listing Assets from multiple Cloud Providers.

An app that helps you monitor your Kubernetes cluster, debug critical deployments & gives recommendations for standard practices

Security Governance for Agentic AI

A utility to detect various technology for a given IP address.

PowerShell-based security assessment framework for Microsoft 365, Azure, and Entra ID. Scans for misconfigurations, CIS benchmark compliance, and…