
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Six Degrees of Domain Admin

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

A tool for quickly evaluating IAM permissions in AWS.

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

A script for advanced discovery of Privileged Accounts - includes Shadow Admins


Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

AWS Identity and Access Management Visualizer and Anomaly Finder

An AWS IAM policy statement parser and query tool.

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…