Rhino Security Labs (@RhinoSecurityLabs)

Top repositories

1

pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
Python
4,015
star
2

cloudgoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
Python
2,428
star
3

Security-Research

Exploits written by the Rhino Security Labs team
Python
1,036
star
4

AWS-IAM-Privilege-Escalation

A centralized source of all AWS IAM privilege escalation methods released by Rhino Security Labs.
883
star
5

IPRotate_Burp_Extension

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.
Python
766
star
6

CVEs

A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs.
Python
750
star
7

ccat

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.
Python
573
star
8

SleuthQL

Python3 Burp History parsing tool to discover potential SQL injection points. To be used in tandem with SQLmap.
Python
460
star
9

GCPBucketBrute

A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.
Python
446
star
10

Cloud-Security-Research

Cloud-related research releases from the Rhino Security Labs team.
Python
346
star
11

GCP-IAM-Privilege-Escalation

A collection of GCP IAM privilege escalation methods documented by the Rhino Security Labs team.
Python
311
star
12

Swagger-EZ

A tool geared towards pentesting APIs using OpenAPI definitions.
JavaScript
163
star
13

Aggressor-Scripts

Aggregation of Cobalt Strike's aggressor scripts.
PowerShell
145
star
14

IAMActionHunter

An AWS IAM policy statement parser and query tool.
Python
137
star
15

dsnap

Utility for downloading and mounting EBS snapshots using the EBS Direct API's
Python
61
star
16

Presentations

A collection of slides, videos, and proof-of-concept scripts from various Rhino presentations.
37
star
17

little-stitch

Send and receive bypassing Little Snitch alerting.
Go
9
star