Skip to content
Change the repository type filter

All

    Repositories list

    • gitleaks

      Public
      Protect and discover secrets using Gitleaks 🔑
      Go
      MIT License
      1.5k100Updated Jul 29, 2023Jul 29, 2023
    • CyberChef

      Public
      The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
      JavaScript
      Apache License 2.0
      3.4k000Updated Jul 29, 2023Jul 29, 2023
    • Go module that returns supported regions for a service or supported services for a region
      Go
      MIT License
      6000Updated Jul 29, 2023Jul 29, 2023
    • checkov

      Public
      Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
      Python
      Apache License 2.0
      1.2k000Updated Jul 28, 2023Jul 28, 2023
    • Python
      261000Updated Jul 28, 2023Jul 28, 2023
    • E-mails, subdomains and names Harvester - OSINT
      Python
      2.1k000Updated Jul 27, 2023Jul 27, 2023
    • An encyclopedia for offensive and defensive security knowledge in cloud native technologies.
      Dockerfile
      Other
      228000Updated Jul 27, 2023Jul 27, 2023
    • pacu

      Public
      The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
      Python
      BSD 3-Clause "New" or "Revised" License
      719000Updated Jul 27, 2023Jul 27, 2023
    • Visualize your aws security groups.
      Ruby
      MIT License
      107000Updated Jul 27, 2023Jul 27, 2023
    • ☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
      Go
      Apache License 2.0
      226000Updated Jul 27, 2023Jul 27, 2023
    • SecLists

      Public
      SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
      PHP
      MIT License
      24k000Updated Jul 27, 2023Jul 27, 2023
    • prowler

      Public
      Prowler is an Open Source Security tool for AWS, Azure and GCP to perform Cloud Security best practices assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.
      Python
      Apache License 2.0
      1.6k000Updated Jul 26, 2023Jul 26, 2023
    • Cloud Security Posture Management (CSPM)
      JavaScript
      GNU General Public License v3.0
      692000Updated Jul 26, 2023Jul 26, 2023
    • terragoat

      Public
      TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
      HCL
      Apache License 2.0
      5.3k000Updated Jul 26, 2023Jul 26, 2023
    • A list of useful payloads and bypass for Web Application Security and Pentest/CTF
      Python
      MIT License
      15k000Updated Jul 26, 2023Jul 26, 2023
    • AWS IAM linting library
      Python
      BSD 3-Clause "New" or "Revised" License
      96000Updated Jul 25, 2023Jul 25, 2023
    • AirIAM

      Public
      Least privilege AWS IAM Terraformer
      Python
      Apache License 2.0
      78000Updated Jul 25, 2023Jul 25, 2023
    • CloudMapper helps you analyze your Amazon Web Services (AWS) environments.
      JavaScript
      BSD 3-Clause "New" or "Revised" License
      818000Updated Jul 25, 2023Jul 25, 2023
    • cloud-bots-azure repo
      Python
      GNU General Public License v3.0
      19000Updated Jul 25, 2023Jul 25, 2023
    • A GPT-empowered penetration testing tool
      Python
      MIT License
      947000Updated Jul 25, 2023Jul 25, 2023
    • Python
      12000Updated Jul 23, 2023Jul 23, 2023
    • Sn1per

      Public
      Attack Surface Management Platform
      Shell
      Other
      1.9k000Updated Jul 22, 2023Jul 22, 2023
    • A collection of awesome penetration testing resources, tools and other shiny things
      4.5k000Updated Jul 21, 2023Jul 21, 2023
    • fuzz.txt

      Public
      Potentially dangerous files
      510000Updated Jul 20, 2023Jul 20, 2023
    • An AWS IAM policy statement parser and query tool.
      Python
      Apache License 2.0
      13000Updated Jul 18, 2023Jul 18, 2023
    • cloudfox

      Public
      Automating situational awareness for cloud penetration tests.
      Go
      MIT License
      192000Updated Jul 18, 2023Jul 18, 2023
    • scantron

      Public
      A distributed nmap / masscan scanning framework complete with scan scheduling, engine pooling, subsequent scan port diff-ing, and an API client for automation workflows.
      Python
      Apache License 2.0
      148000Updated Jul 17, 2023Jul 17, 2023
    • cloudgoat

      Public
      CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
      Python
      BSD 3-Clause "New" or "Revised" License
      644000Updated Jul 14, 2023Jul 14, 2023
    • Multi-Cloud Security Auditing Tool
      Python
      GNU General Public License v2.0
      1.1k000Updated Jul 14, 2023Jul 14, 2023
    • Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.
      209000Updated Jul 14, 2023Jul 14, 2023