
AzureC2Relay
Azure Function that validates and relays Cobalt Strike beacon traffic using malleable C2 profiles, redirecting invalid requests to a decoy site and…

Azure Function that validates and relays Cobalt Strike beacon traffic using malleable C2 profiles, redirecting invalid requests to a decoy site and…

Secure runtime to sandbox AI agent tasks. Run untrusted code in isolated WebAssembly environments.

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

A tool for pointesters to find candies in SharePoint

Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

A tool to hunt for publicly accessible DigitalOcean Spaces

End to End testing of Web, API, Cloud, Events and Security

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

Automated security findings enrichment and impact evaluation tool for AWS. Enriches vulnerability data with resource context, associations, and tags…

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.

A simple file-based scanner to look for potential AWS access and secret keys in files

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS