
google-dorks
Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…

Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…



Snyk CLI scans and monitors your projects for security vulnerabilities.

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

AWSGoat : A Damn Vulnerable AWS Infrastructure

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

PowerShell-based security assessment framework for Microsoft 365, Azure, and Entra ID. Scans for misconfigurations, CIS benchmark compliance, and…

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational…

AzureGoat : A Damn Vulnerable Azure Infrastructure

Curated timeline of AWS S3 bucket misconfigurations, exposed data, and leaked IAM credentials, with incident links for cloud security defenders and…

Getting a handle on container security

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

AWS Auditing & Hardening Tool

Open-source cloud security platform that discovers attack paths, identifies misconfigurations, visualizes IAM access, and provides step-by-step…

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

My cheatsheet notes to pentest AWS infrastructure

Library and CLI tool for analysing CloudFormation templates and check them for security compliance.