Stars
ASEA developer support has ended, and the ASEA github repo will be marked Archived (read-only) by the end of 2025.
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
Sample code for integrating AWS CloudFormation templates security tests (using CFN-Nag and CFN-Guard) with both AWS Security Hub and AWS CodeBuild reports.
SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS
Automated Security Response on AWS is an add-on solution that works with AWS Security Hub to provide a ready-to-deploy architecture and a library of automated playbooks. The solution makes it easie…
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
StepFunctions Demo -- Encrypt EBS volumes from AWS EC2 instances with a serverless StepFunctions machine
A combined list of helpful awscli commands from Scott Piper's flaws.cloud exercise as well as from Beau Bullock's Breaching the Cloud Training
The AWS KMS JCE Provider software library for Java is a vendor implementation for the Sun Java JCE (Java Cryptography Extension) provider framework with a focus on using asymmetric keys to sign and…
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
An automated target reconnaissance pipeline.
Fetch all the URLs that the Wayback Machine knows about for a domain
GoFingerprint is a Go tool for taking a list of target web servers and matching their HTTP responses against a user defined list of fingerprints.
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …
Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
Take a list of domains and probe for working HTTP and HTTPS servers
A collection of tools to perform searches on GitHub.
Fast passive subdomain enumeration tool.
In-depth attack surface mapping and asset discovery