
TokenMan
Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

Java SDK for integrating with Amazon Web Services, providing secure API access to S3, DynamoDB, EC2, and more, with built-in authentication,…

Proof-of-concept exploit for CVE-2021-38647 (OMIGOD), an unauthenticated remote code execution vulnerability in the OMI agent commonly deployed on…

Proof of concept for CVE-2020-15257 in containerd.

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

A collection of scripts for assessing Microsoft Azure security

A container analysis and exploitation tool for pentesters and engineers.

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

Proof-of-concept exploit and advisory for CVE-2026-54356, a Budibase missing-authorization flaw that lets low-privilege users mint S3 pre-signed…

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

barq: The AWS Cloud Post Exploitation framework!

Azure Post Exploitation Framework

Automated Persistence and Lateral Movement using GCP Patch Management

Exploits CVE-2026-21005 by poisoning Docker Registry V2 Schema 1 manifests via unauthenticated pushes, enabling tag overwrite and supply-chain…

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

Post-quantum hybrid encryption library combining X25519 + ML-KEM-768 with AES-256-GCM

Chef cookbook to detect and patch the Shellshock (CVE-2014-7169) bash vulnerability across servers using automated configuration management.