
yatas
:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

A tool to hunt for publicly accessible DigitalOcean Spaces

The only open-source tool to analyze vulnerabilities and configuration issues with running docker container(s) and docker networks.

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…


A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

Discover resources created in an AWS account.

Linting tool for CloudFormation templates

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…