
GPOHound
Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

Scan for misconfigured S3 buckets across S3-compatible APIs!

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

A tool to scan Kubernetes cluster for risky permissions

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

AD Enum is a pentesting tool that allows to find misconfiguration through the the protocol LDAP and exploit some of those weaknesses with kerberos.

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

Tool designed to help identify incorrectly configured Django applications that are exposing sensitive information.

Black-box Kubernetes attack surface discovery tool that probes for unsecured clusters, exposed dashboards, and misconfigurations using…

🦁 Python project to identify and scan for vulnerabilities related to the Joomla CMS project. It scans for common misconfigurations and public…

A tool to hunt for publicly accessible DigitalOcean Spaces

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…


Pentester-focused Docker registry tool to enumerate and pull images