
cve-2021-43858
Exploit for MinIO privilege escalation vulnerability CVE-2021-43858, allowing unauthorized access to cloud storage. Written in Go, run with 'go run…

Exploit for MinIO privilege escalation vulnerability CVE-2021-43858, allowing unauthorized access to cloud storage. Written in Go, run with 'go run…

Directory/File, DNS and VHost busting tool written in Go

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

A high-performance, eBPF-based network traffic analyzer written in Rust.

A fast tool to scan SAAS,PAAS App written in Go

Detects and exploits MinIO information disclosure vulnerability (CVE-2023-28432) with single and batch URL scanning, written in Go.

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

A tool to hunt for publicly accessible DigitalOcean Spaces

Module-based AWS exploitation framework for red team testing and blue team analysis. Emulates attack patterns in the AWS control plane with unique UA…

Faraday Agent Dispatcher launches any security tools and send results to Faradaysec Platform.


Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

Collection of offensive tools targeting Microsoft Azure

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

A collection of AWS penetration testing junk