
honeyLambda
honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Cloud native secrets management for developers - never leave your command line for secrets.

Providing Azure pipelines to create an infrastructure and run Atomic tests.

Privilege Escalation using nodes/proxy (create action allowed) and nodes/status (update/patch actions allowed)

Blue Team detection lab created with Terraform and Ansible in Azure.

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

Reconnaissance Real IP address for Cloudflare Bypass

Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scanning — applied…

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

Proof-of-concept exploit for CVE-2022-27518 targeting Citrix ADC and Citrix CPX containers, demonstrating remote code execution via crafted HTTP…

Create On Demand Disposable OpenVPN Endpoints on AWS.

A collection of manifests that will create pods with elevated privileges.

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

Create your own vulnerable by design AWS penetration testing playground

TunnelX is a lightweight ingress tunneling tool designed to create a secure SOCKS5 proxy server for routing network traffic.

Verification script for CVE-2025-62506, a privilege escalation vulnerability in MinIO service accounts, testing if restricted accounts can bypass…