
cliam
Cloud agnostic IAM permissions enumerator

Cloud agnostic IAM permissions enumerator

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

GCP resource scanner that evaluates access levels of compromised credentials by enumerating cloud services, projects, and IAM permissions across…

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

Internal network scanner through Gluu IAM blind ssrf

Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services

AWS Identity and Access Management Visualizer and Anomaly Finder

Six Degrees of Domain Admin

PowerShell MachineAccountQuota and DNS exploit tools

In-depth ldap enumeration utility


SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…