
security-study-plan
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

My cheatsheet notes to pentest AWS infrastructure

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

Manual black-box penetration test of hosting provider infrastructure using curl_cffi and Python. Identifies exposed databases, default credentials,…

Username enumeration and password spraying tool aimed at Microsoft O365.

Terraform-based Azure security lab generator for purple teaming, creating customizable environments with Active Directory, Sentinel, managed…

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

The Swiss Army Container for Cloud Native Security. Container with all the list of useful tools/commands while hacking and securing Containers,…

Customizable password spraying tool for Microsoft accounts (Office 365/Azure AD) with execution plans, Smart Lockout bypass, and audit mode for…

Automated reconnaissance tool that performs subdomain enumeration, vulnerability scanning, OSINT, port scanning, and web analysis to map attack…

SSRF (Server Side Request Forgery) testing resources

Collection of quality safety articles. Awesome articles.

Enumerates valid Microsoft 365 users via OneDrive URL status codes (403 vs 404). Supports threaded wordlists, username mutation, tenant lookup, and…

Modular penetration testing tool for cloud container environments. Enumerates ECR repositories, backdoors Docker images, and exploits…