Stars
Azure Security Resources and Notes
BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and configurable, traversable attack paths.
A Post-exploitation Toolset for Interacting with the Microsoft Graph API
A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post
CORS Anywhere is a NodeJS reverse proxy which adds CORS headers to the proxied request.
Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI
OWASP Foundation web repository
Research into Undocumented Behavior of Azure AD Refresh Tokens
Collection of powershell scripts I used to complete my CARTP and CARTE courses.
FULL Augment Code, Claude Code, Cluely, CodeBuddy, Comet, Cursor, Devin AI, Junie, Kiro, Leap.new, Lovable, Manus Agent Tools, NotionAI, Orchids.app, Perplexity, Poke, Qoder, Replit, Same.dev, Trae…
Collection of extracted System Prompts from popular chatbots like ChatGPT, Claude & Gemini
Collection of extracted System Prompts from popular chatbots like ChatGPT, Claude & Gemini
A tool for checking if MFA is enabled on multiple Microsoft Services
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAR…
A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, i…
PowerShell framework to assess Azure security
Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advanced techniques to dump memory, allowing to access sensitive da…
A collection of scripts for assessing Microsoft Azure security
This repository contains cutting-edge open-source security notes and tools that will help you during your Red Team assessments.
A simple python script that will generate 2-6 machine names from the now infamous "Lainkusanagi & TJ Null OSCP trophy list".
Automated Tool for Testing Header Based Blind SQL Injection
An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws