Cloud-Security
2026-08-28
Rust
★ 39
Stratum C2 is a cloud persistence framework designed to maintain command-and-control (C2) communication through trusted cloud storage providers like Dropbox and OneDrive, thus avoiding detection by traditional security defenses. Its notable features include end-to-end encryption with RSA and AES, the ability to switch between multiple cloud providers seamlessly, and a structurally unblockable channel that makes it difficult for security operations centers to intercept. The framework supports multiple agent formats for both Windows and Linux without requiring additional dependencies.
2026-08-14
Shell
★ 21
opencode-pentester is an AI-powered penetration testing and security audit framework designed to automate bug bounty hunting and vulnerability assessments. It orchestrates 12 specialized AI agents across 69 attack categories and 17 OWASP security audits, enabling comprehensive offensive and defensive testing. Notable features include the ability to run automated tests, generate professional reports, and integrate a wide array of security tools, making it suitable for security researchers, penetration testers, and DevSecOps engineers.
2026-08-12
Python
★ 158
AI for the Win is a hands-on training platform designed for security practitioners to develop AI-powered tools specifically for threat detection, incident response, and security automation. It features over 50 labs, including capstone projects and CTF challenges, focusing on practical applications such as phishing detection and security log analysis using advanced algorithms like Random Forest and LLMs. The platform also offers a Docker lab environment, sample datasets, and solution walkthroughs to facilitate immersive learning experiences.
2026-08-03
Shell
★ 16
IAM-Flaws is a bash script designed to identify misconfigurations in AWS IAM User and Group Policy Permissions, facilitating privilege escalation assessments. Its primary use case involves conducting CIS Benchmark checks, enumerating IAM entities (users, groups, policies), and scanning for potential privilege escalation vulnerabilities. Notable features include a modular design for executing various checks independently, as well as an integrated output logging mechanism for comprehensive analysis.
2026-08-03
Python
★ 60
The GCP-Attack-Defense project provides comprehensive documentation of attack and defense vectors specifically in the Google Cloud Platform (GCP), aiding users in understanding security threats and mitigation strategies. It features detailed research on various aspects of cloud security, including privilege escalation and defense evasion, as well as tools like gLess and GATOR for practical application. The project serves both as an educational resource and a reference for cybersecurity professionals studying GCP vulnerabilities.
2026-08-03
TypeScript
★ 19
Cloud-audit-mcp is a cloud security auditing tool designed for AI agents to directly interact with cloud APIs, allowing for real-time checks, correlation of findings, and automated remediation of vulnerabilities. Unlike traditional tools that produce static reports requiring human analysis, this tool enables the AI to prioritize issues and generate specific commands for fixes, streamlining the security auditing process across multi-cloud environments such as AWS, Azure, and GCP. Notable features include the ability for the AI to chain checks, assess context, and follow up on remediation efforts without needing to re-scan the whole environment.
2026-08-03
Python
★ 272
Kosty is a comprehensive CLI tool designed for AWS cost optimization and security auditing, capable of scanning over 30 AWS services. Its key features include external attack surface mapping, IAM privilege escalation detection, and specific audits for GenAI workloads like Bedrock and SageMaker, alongside actionable insights on cost savings and security gaps. The tool facilitates organization-wide scanning with parallel processing and offers an interactive visual dashboard for in-depth report analysis.
2026-08-03
Python
★ 46
AWSATT&CK is a modified version of the open-source AWS exploitation framework, Pacu, designed to add MITRE ATT&CK context to its tactics and enhance logging capabilities. This tool is primarily used for post-exploitation within AWS environments, featuring quick execution functions, event logging to SIEM solutions, and scalability enhancements to streamline security operations. Notable features include the integration of MITRE ATT&CK techniques, agile deployment options, and a focus on flexibility for security professionals tackling diverse IT and cloud-native challenges.
2026-08-03
Python
★ 55
OpenShield is an open-source Cloud Security Posture Management (CSPM) tool designed specifically for Azure environments, enabling users to detect misconfigurations and improve security compliance by mapping issues to frameworks like CIS, NIST, and ISO 27001. Notable features include a comprehensive misconfiguration scanner, which evaluates over fifty security rules across various Azure services, and the ability to identify classical cryptographic assets that require migration to quantum-safe alternatives. The tool facilitates remediation through a single command, providing a user-friendly approach to enhancing cloud security for startups and small to medium-sized enterprises.
2026-08-03
Go
★ 194
Cynative is a read-only cybersecurity tool designed for deep infrastructure research, allowing users to query various systems such as GitHub, GitLab, AWS, GCP, Azure, and Kubernetes in a unified manner. It executes code in an ephemeral sandbox to provide verified insights while maintaining strict access controls, thereby ensuring that users can confidently audit their cloud environments without compromising security. Notable features include its ability to reason through code-to-runtime environments, a robust action-gate mechanism for authorization, and evidence-backed findings that trace back to their origins.
2026-08-03
★ 17
The 'suspicious_IPs' repository provides a compiled list of potentially malicious or harmful IP addresses. Its primary use case is for cybersecurity professionals to enhance threat detection and mitigation measures by identifying and blocking traffic from these suspicious IPs. Notable features include a straightforward format that allows for easy integration into firewall rules and intrusion detection systems.
2026-08-03
Python
★ 15
X-POSURE v4.0 is an autonomous credential intelligence platform designed for discovering, extracting, correlating, verifying, and reporting exposed secrets across an organization's entire attack surface. Its primary use case is to enhance security by identifying vulnerabilities related to exposed credentials, further augmented with features like recursive crawling, Shodan integration, AI-powered contextual analysis, and deep secrets scanning via TruffleHog. This tool is engineered for advanced users who recognize the significance of credential exposure as a substantial security threat.
2026-08-03
Python
★ 11
CloudVault is an enterprise-grade security scanner designed for multi-cloud storage environments, specifically targeting AWS S3, Google Cloud Storage, and Azure Blob. It offers advanced attack chain analysis, automated permission checking, and comprehensive risk scoring, facilitating real-time discovery of exposed cloud resources through certificate transparency monitoring. Notable features include interactive text user interface (TUI), alerts integration with communication platforms, compliance mapping, and various export formats for reporting and remediation.
2026-08-03
JavaScript
★ 27
Pentesting Cyber MCP is a framework that provides standardized server implementations for 50 popular security tools via the Model Context Protocol (MCP), facilitating automation in pentesting and bug bounty tasks. Each MCP server encapsulates a security tool with a uniform interface, making it interoperable with any MCP-compatible client and allowing seamless integration into security assessments. Notable features include a wide range of tools covering reconnaissance, vulnerability scanning, and exploitation, all accessible through standard MCP interfaces.
2026-08-03
Python
★ 69
cloud-audit is an open-source AWS security scanning tool designed to identify attack paths, IAM escalation routes, and prioritize necessary fixes based on their impact on security. It operates in a read-only mode, ensuring no modifications are made to the user's AWS infrastructure while providing detailed reports on correlations between vulnerabilities and suggested remediation steps, including AWS CLI and Terraform fixes per finding. Key features include the identification of attack chains using MITRE ATT&CK methodology, root-cause analysis for prioritized fixes, and a simulation function to evaluate the potential impact of proposed changes.
2026-08-03
Go
★ 175
Drogonsec is an open-source security scanner designed to perform comprehensive security assessments through Static Application Security Testing (SAST), Software Composition Analysis (SCA), and secret detection, aligning with the OWASP Top 10:2025 framework. It supports over 20 programming languages and various deployment strategies, including local or cloud-based AI remediation for findings. Key features include the ability to scan for vulnerabilities, identify misconfigurations in Infrastructure as Code (IaC), and integrate with CI/CD pipelines for automated security reporting.
2026-08-03
Python
★ 24
claude-code-pentest automates the penetration testing lifecycle using six specialized skills that range from reconnaissance to exploit chaining and report generation. Its notable features include subdomain enumeration, vulnerability discovery across web applications and APIs, cloud infrastructure analysis, and the capability to compose findings into comprehensive bug bounty reports—all implemented via 43 standalone Python scripts that require no external dependencies. The tool is designed for authorized security testing only and is integrated with Claude Code for user-friendly command execution.
2026-08-03
Python
★ 345
Halberd is an open-source, multi-cloud attack emulation tool designed to help cybersecurity professionals validate their cloud security defenses across major platforms such as Azure, AWS, GCP, Entra ID, and M365. It offers over 120 pre-built attack techniques mapped to MITRE ATT&CK and Azure TRM frameworks, an AI-powered intelligence mechanism for discovering and executing attack paths, and a user-friendly web interface that eliminates the need for command-line expertise, facilitating automation, orchestration, and reporting for cloud security testing.
2026-08-03
★ 16
The "Awesome Cybersecurity Tools" repository serves as a comprehensive catalog of security tools aimed at students, red/blue teams, and cybersecurity professionals. It categorizes a wide range of tools across various domains, including reconnaissance, web application testing, cloud security, and digital forensics, ensuring that users have access to well-maintained and widely utilized software for security testing and defensive research. Notable features include a structured navigation system for efficient lookups and a strong emphasis on responsible and authorized usage of listed tools.
2026-08-03
★ 137
Cloud OSINT is a curated resource designed for conducting open-source intelligence (OSINT) assessments of cloud infrastructure, featuring dorks, tools, techniques, and methodologies applicable across major cloud platforms such as AWS, Azure, GCP, Oracle, and IBM. Its primary use case is to assist security professionals, red teamers, and bug bounty hunters in effectively mapping and analyzing cloud environments through a structured reconnaissance workflow. Notable features include comprehensive guidance on cloud infrastructure patterns, domain identification, and a variety of targeted dork queries, enhancing the efficiency of reconnaissance efforts.
2026-08-03
Python
★ 53
PWNCLOUDOS is a multi-cloud security Linux distribution designed for both offensive and defensive security operations across major cloud platforms such as AWS, Azure, and GCP. It offers a lightweight XFCE4 environment pre-loaded with a range of cloud exploitation tools, auditing frameworks, and security testing utilities, making it suitable for red, blue, and purple teams. Notable features include customizable shell environments, a variety of cloud-specific tools, and community-driven enhancements, with options for both AMD64 and ARM64 architectures.
2026-08-03
HTML
★ 80
The Security Reference Guide is a curated repository of cyber security resources tailored for SOC analysts, pentesters, DFIR practitioners, and other security-focused roles. It organizes valuable links into categories such as offensive and defensive operations, engineering fundamentals, and training resources, providing context to help users select the appropriate tools and materials quickly. Notably, the guide emphasizes legitimacy, cautioning against the misuse of tools for unethical purposes.
2026-08-03
Python
★ 29
The Cloud Security Toolkit is a comprehensive resource designed for offensive security practitioners focused on cloud environments, facilitating the exploitation of vulnerabilities and simulating advanced attacks specifically within platforms like Azure, AWS, and Microsoft 365. Notable features include a collection of weaponized exploits, deep-dive vulnerability research, threat intelligence insights, and evasion techniques targeted at cloud defense systems, all aimed at enhancing red team operations and improving cloud security assessments. This toolkit provides practical, battle-tested resources essential for sophisticated penetration testing and incident response in cloud ecosystems.
2026-08-03
Shell
★ 14
Omniscient V3 is a comprehensive reconnaissance and adversary simulation framework designed to enhance security assessments by consolidating over 130 best-in-class tools into a unified pipeline. Key features include AI-driven results augmentation, distributed execution across platforms such as Kubernetes and Docker, advanced stealth techniques for emulating sophisticated attacks, and immutable audit trails for compliance and reporting. This tool is primarily aimed at security professionals, providing a streamlined approach to identifying vulnerabilities in complex attack surfaces.
2026-08-03
Python
★ 476
Cain is an AI-powered penetration testing engine designed for authorized security assessments in real-world environments, effectively navigating complex business logic and adapting to activated WAF/risk control systems. Key features include a cloud penetration module that supports major cloud platforms, a deterministic state machine for orchestrated testing, and robust safety mechanisms ensuring compliance and risk management. Its capabilities extend to identifying business logic flaws, authentication issues, and cloud misconfigurations, providing detailed evidence and actionable remediation advice.
2026-08-03
Python
★ 1214
Recon Skills is a comprehensive toolkit designed for authorized security testing, focusing on external reconnaissance across web applications, APIs, and various vulnerability assessments. Notable features include a structured catalog of skills for discovery, validation, and reporting, covering areas such as authentication testing, attack-path analysis, and evidence review, while emphasizing best practices for operational security and quality assurance. The tool aims to facilitate both manual and automated workflows for security professionals, ensuring a thorough approach to web security assessments.
2026-08-03
Python
★ 880
DarkMoon is an open-source, AI-powered autonomous penetration testing platform designed to conduct end-to-end security assessments without manual intervention. Notable features include a privacy gateway that ensures sensitive data remains secure, integration with over 50 pen-testing tools, and automated vulnerability reporting. This tool is particularly advantageous for security teams and DevSecOps engineers seeking to streamline and scale their defensive operations while maintaining strict data sovereignty.
2026-03-22
Python
★ 31783
734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI & 20+ platforms · Penetration testing, DFIR, threat intel, cloud security & more · Apache 2.0
2026-03-22
★ 1533
Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security
2026-03-22
CSS
★ 950
Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!
2026-03-22
Go
★ 1146
Awesome cloud enumerator
2026-03-22
Shell
★ 1167
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
2026-03-22
Python
★ 1036
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks
2026-03-22
HTML
★ 5448
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
2026-03-22
Rust
★ 1663
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
2026-03-22
PowerShell
★ 1323
Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Microsoft Entra ID security configuration reviews.
2026-03-22
Shell
★ 9415
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
2026-03-22
★ 1169
A Huge Learning Resources with Labs For Offensive Security Players
2026-03-22
★ 5051
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
2026-03-22
PowerShell
★ 912
SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS
2026-03-22
C++
★ 16732
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.