
owasp-cstg
Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Cross-platform Electron GUI for the Sliver C2 framework, providing session and beacon dashboards, payload generation, listeners, loot, and cloud…

Automating situational awareness for cloud penetration tests.

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

Module-based AWS exploitation framework for red team testing and blue team analysis. Emulates attack patterns in the AWS control plane with unique UA…

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

AzureRT - A Powershell module implementing various Azure Red Team tactics

Fawkes is a golang Mythic C2 Agent exclusively written by AI.