
nuvola
Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

Vulnerable-by-design AWS deployment tool for hands-on cloud security training. Deploys curated CTF scenarios to practice IAM enumeration, privilege…

Multi-function web security assessment tool combining XSS, SSRF, SQL injection testing, subdomain enumeration, Whois lookup, CORS and AWS S3…

Python tool for AWS S3 bucket takeover: exploits misconfigured buckets by uploading a file to claim ownership. Used in penetration testing and cloud…

Multi-cloud vulnerable-by-design environment deployment tool for practicing detection and exploitation of cloud security misconfigurations across…

Modular penetration testing tool for cloud container environments. Enumerates ECR repositories, backdoors Docker images, and exploits…

S3 bucket enumerator for blackbox and whitebox security audits. Scans via domains, keywords, or AWS credentials to detect exposed buckets and…

Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

A tool for quickly evaluating IAM permissions in AWS.

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

Automating situational awareness for cloud penetration tests.

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

A tool to hunt for publicly accessible DigitalOcean Spaces

An AWS IAM policy statement parser and query tool.

A tool to enumerate S3 buckets manually or via certstream

AWS Testing and Reporting Management Tool

Extensible Azure Security Tool - Documentation

Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…