top
Checklist of the most important security countermeasures when designing, testing, and releasing your API
Peirates - Kubernetes Penetration Testing tool
🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
Azure Red Team tool for graphing Azure and Azure Active Directory objects
Adversarial Robustness Toolbox (ART) - Python Library for Machine Learning Security - Evasion, Poisoning, Extraction, Inference - Red and Blue Teams
PowerShell framework to assess Azure security
Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI
A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.