
shimit
A tool that implements the Golden SAML attack

A tool that implements the Golden SAML attack

Automated network asset, email, and social media profile discovery and cataloguing.

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

Python reconnaissance tool for discovering Azure services and attributing tenant ownership via DNS validation, multi-service probing, and response…

Automated Bitwarden vault backup tool with AES-256 encryption, Argon2 key derivation, multi-cloud upload support, and real-time notifications via…

AWS AMAZON S3 Bucket Takeover Scanner & Claim Tool

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

A tool to hunt for publicly accessible DigitalOcean Spaces

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

The PQC Network Scanner is a quantum‑focused network assessment tool that scans TLS/SSL certificates across enterprise environments to identify…

A tool for quickly evaluating IAM permissions in AWS.

Security Tool to Look For Interesting Files in S3 Buckets

Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Username enumeration and password spraying tool aimed at Microsoft O365.

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace