☁️Cloud
A tool leveraging Kerberos tickets to get Microsoft 365 access tokens using Seamless SSO
DelePwn is a security assessment tool designed to identify and demonstrate the risks associated with Google Workspace Domain-Wide Delegation (DWD) misconfigurations in Google Cloud Platform (GCP) e…
TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and penetration tests with the tokens generated working out of t…
Azure Security Resources and Notes
Dump Azure AD Connect credentials for Azure AD and Active Directory
Modular cross-platform Microsoft Graph API (Entra, o365, and Intune) enumeration and exploitation toolkit
Azure Red Team tool for graphing Azure and Azure Active Directory objects
Lightweight security tool for auditing your organization's Conditional Access Policies (CAPs) in Microsoft Entra ID for potential misconfigurations.
Enumeration/exploit/analysis/download/etc pentesting framework for GCP; modeled like Pacu for AWS; a product of numerous hours via @WebbinRoot
Tool to quickly enumerate IAM permissions for a Google Cloud Platform (GCP) account
Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy
Sample Generative AI tool for evaluating Infrastructure as Code and architecture diagrams against AWS Well-Architected best practices.
Python script to render / generate flow chart like visual of IAM policy
A comprehensive list of usable Entra ID first-party clients with pre-consented Microsoft Graph scopes, in a simple YAML-file explorable with a simple HTML GUI.
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
A simple Python script to do quick, targeted recon of a given domain.
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.