
AWS-Threat-Simulation-and-Detection
Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic

Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

Proof-of-concept demonstrating SSRF and HTTP header injection in KubePlus ResourceComposition, enabling cloud metadata access and IAM credential…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Serverless task distribution framework that parallelizes CLI tools across thousands of cloud functions for rapid reconnaissance and data processing.

Microsoft Sentinel SIEM Log Source Analyzer

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

An Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

Writeup of CVE-2017-1002101 with sample "exploit"/escape

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Search exposed EBS volumes for secrets

Read-only AWS service enumerator with 600+ API calls for cloud reconnaissance, info dumping, and result analysis during penetration testing.

Cloud agnostic IAM permissions enumerator