
GPOHound
Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

Automating the MITM attack on WSUS

Find exposed data in Azure with this public blob scanner

A tool for identifying misconfigured CloudFront domains

AD Enum is a pentesting tool that allows to find misconfiguration through the the protocol LDAP and exploit some of those weaknesses with kerberos.

Find cloud assets that no one wants exposed 🔎 ☁️

Black-box Kubernetes attack surface discovery tool that probes for unsecured clusters, exposed dashboards, and misconfigurations using…

Scans DNS MX records to detect misconfigured, expiring, or unregistered domains vulnerable to email takeover, with automatic reclamation support for…

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

Authorized cloud adversary simulation and validation toolkit

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

Pentester-focused Docker registry tool to enumerate and pull images