
o365-attack-toolkit
A toolkit to attack Office365

A toolkit to attack Office365

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

An at-rest encrypted filesharing application with multiple clients who seek to share privately, without tracking.

Exploit for Apache NiFi CVE-2023-34468, targeting a vulnerability in versions 1.21.0 and earlier to demonstrate data access and system compromise.

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace

Azure Post Exploitation Framework

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

Scan for open S3 buckets and dump

Automated phishing campaign toolset that spawns dedicated AWS EC2 instances with integrated PhishingFrenzy and BeEF, plus subdomain discovery and…

Go toolkit for authorized Azure security assessments: enumerates subscriptions and resources, audits misconfigurations, and attacks public Blob…

Cloud Storage using Instagram.

CVE-2023-28432 MinIO敏感信息泄露检测脚本

Syncord is a CLI-based file synchronization and storage tool that uses Discord as an encrypted file storage.

CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)