
cliam
Cloud agnostic IAM permissions enumerator

Cloud agnostic IAM permissions enumerator

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

GCP resource scanner that evaluates access levels of compromised credentials by enumerating cloud services, projects, and IAM permissions across…

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

Tool to spray AWS Console IAM Logins

Bash and PowerShell scripts for Azure security assessments, covering IAM privilege escalation, container registry exploitation, Key Vault exposure,…

Proof-of-concept exploit for CVE-2024-9513 targeting user enumeration in NetAdmin IAM via HTTP POST request to…

Sistema NetAdmin IAM 4 é vulnerável a Cross Site Scripting (XSS), no endpoint /BalloonSave.ashx

Search exposed EBS volumes for secrets

Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services

AWS Identity and Access Management Visualizer and Anomaly Finder

Six Degrees of Domain Admin

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

A tool to scan Kubernetes cluster for risky permissions

In-depth ldap enumeration utility