Stars
☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
Research into Undocumented Behavior of Azure AD Refresh Tokens
A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS accounts.
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …
The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving to…
RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.
Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.
A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale.
A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.
Checklist of the most important security countermeasures when designing, testing, and releasing your API
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
Vulnerable REST API with OWASP top 10 vulnerabilities for security testing
Autoswagger by Intruder - detect API auth weaknesses
R-s0n / cloud_enum
Forked from initstring/cloud_enumMulti-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
A comprehensive security checklist for MCP-based AI tools. Built by SlowMist to safeguard LLM plugin ecosystems.
Chris Titus Tech's Windows Utility - Install Programs, Tweaks, Fixes, and Updates
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
Lightweight security tool for auditing your organization's Conditional Access Policies (CAPs) in Microsoft Entra ID for potential misconfigurations.
Simple hunting script for suspicious M365 OAuth Apps
A tool to wrap Win32 App and then it can be uploaded to Intune
Repo that hold write-ups of various research projects I did and/or overall InfoSec things I investigated/researched.
Python tool for converting files and office documents to Markdown.
RequestShield is a 100% Free and OpenSource tool designed to analyze HTTP access.logs and identify suspicious HTTP requests and potential security threats. It uses factors like geolocation, abuse h…
Tool for Active Directory Certificate Services enumeration and abuse