• Stars
    star
    633
  • Rank 68,647 (Top 2 %)
  • Language
  • Created almost 3 years ago
  • Updated over 1 year ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Awesome-Cloud-PenTest

Cloud PenTest - AWS and Azure by Joas

What is AWS

Extras Resources

My Social Networks

What is Azure

PenTest Policy

PenTest in AWS

AWS Security

PenTest in Azure

  • Enumeration

  • o365creeper - Enumerate valid email addresses

  • CloudBrute - Tool to find a cloud infrastructure of a company on top Cloud providers

  • cloud_enum - Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud

  • Azucar - Security auditing tool for Azure environments

  • CrowdStrike Reporting Tool for Azure (CRT) - Query Azure AD/O365 tenants for hard to find permissions and configuration settings

  • ScoutSuite - Multi-cloud security auditing tool. Security posture assessment of different cloud environments.

  • BlobHunter - A tool for scanning Azure blob storage accounts for publicly opened blobs

  • Grayhat Warfare - Open Azure blobs and AWS bucket search

  • Information Gathering

  • o365recon - Information gathering with valid credentials to Azure

  • Get-MsolRolesAndMembers.ps1 - Retrieve list of roles and associated role members

  • ROADtools - Framework to interact with Azure AD

  • PowerZure - PowerShell framework to assess Azure security

  • Azurite - Enumeration and reconnaissance activities in the Microsoft Azure Cloud

  • Sparrow.ps1 - Helps to detect possible compromised accounts and applications in the Azure/M365 environment

  • Hawk - Powershell based tool for gathering information related to O365 intrusions and potential breaches

  • Microsoft Azure AD Assessment - Tooling for assessing an Azure AD tenant state and configuration

  • Lateral Movement

  • Stormspotter - Azure Red Team tool for graphing Azure and Azure Active Directory objects

  • AzureADLateralMovement - Lateral Movement graph for Azure Active Directory

  • SkyArk - Discover, assess and secure the most privileged entities in Azure and AWS

  • Exploitation

  • MicroBurst - A collection of scripts for assessing Microsoft Azure security

  • azuread_decrypt_msol_v2.ps1 - Decrypt Azure AD MSOL service account

  • Credential Attacks

    • MSOLSpray - A password spraying tool for Microsoft Online accounts (Azure/O365)
    • MFASweep - A tool for checking if MFA is enabled on multiple Microsoft Services Resources
    • adconnectdump - Dump Azure AD Connect credentials for Azure AD and Active Directory
  • Abusing Azure AD SSO with the Primary Refresh Token

  • Abusing dynamic groups in Azure AD for Privilege Escalation

  • Attacking Azure, Azure AD, and Introducing PowerZure

  • Attacking Azure & Azure AD, Part II

  • Azure AD Connect for Red Teamers

  • Azure AD Introduction for Red Teamers

  • Azure AD Pass The Certificate

  • Azure AD privilege escalation - Taking over default application permissions as Application Admin

  • Defense and Detection for Attacks Within Azure

  • Hunting Azure Admins for Vertical Escalation

  • Impersonating Office 365 Users With Mimikatz

  • Lateral Movement from Azure to On-Prem AD

  • Malicious Azure AD Application Registrations

  • Moving laterally between Azure AD joined machines

  • CrowdStrike Launches Free Tool to Identify and Help Mitigate Risks in Azure Active Directory

  • Privilege Escalation Vulnerability in Azure Functions

  • Azure Application Proxy C2

  • Recovering Plaintext Passwords from Azure Virtual Machines like It’s the 1990s

  • Azure Articles from NetSPI

  • Azure Cheat Sheet on CloudSecDocs

  • Resources about Azure from Cloudberry Engineering

  • Resources from PayloadsAllTheThings

  • Encyclopedia on Hacking the Cloud - (No content yet for Azure)

  • azure-security-lab - Securing Azure Infrastructure - Hands on Lab Guide

  • AzureSecurityLabs - Hands-on Security Labs focused on Azure IaaS Security

  • Building Free Active Directory Lab in Azure

  • https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md

  • https://github.com/MicrosoftDocs/azure-docs/blob/master/articles/security/fundamentals/pen-testing.md

  • https://github.com/swiftsolves-msft/AzurePenTestScope

Azure Security

More Repositories

1

OSCE3-Complete-Guide

OSWE, OSEP, OSED, OSEE
2,336
star
2

Guide-CEH-Practical-Master

1,064
star
3

Awesome-Red-Team-Operations

1,039
star
4

Cloud-Security-Attacks

Azure and AWS Attacks
1,022
star
5

Red-Team-Management

HTML
522
star
6

Offensivesecurity-Checklists

Checklists for Testing Security environment
493
star
7

Awesome-Malware-and-Reverse-Engineering

343
star
8

eWPTX-Preparation

299
star
9

Python-for-Security

HTML
291
star
10

Awesome-Hardware-and-IoT-Hacking

208
star
11

GCP-Pentest-Checklist

195
star
12

OSCP-Survival-Guide

156
star
13

PNPT-Preparation-Guide

PNPT Exam Preparation - TCM Security
148
star
14

information-security-relatory

Reports from various areas of information security
134
star
15

eWPT-Preparation

132
star
16

awesome-flipperzero2

Compilation of contents about Flipper Zero
121
star
17

eCXD-Preparation

eLearnSecurity Certified Exploit Development
98
star
18

Awesome-Blue-Team-Operations

94
star
19

PenTest-Consulting-Creator

Repository with some necessary information for you to create your PenTest consultancy
92
star
20

Awesome-PenTest-Practice

Hackthebox, Vulnhub, TryHackMe and Real World PenTest
92
star
21

PenTest-Certifications-Roadmap

79
star
22

Buffer-Overflow-Labs

Practice Labs
76
star
23

Awesome-Exploit-Development

69
star
24

RedTeam-Scripts

PowerShell
69
star
25

OSCP-in-one-month

67
star
26

BadPDF-Generator

Python
62
star
27

Template-CherryTree-PenTest

57
star
28

Adversary-Emulation-Matrix

56
star
29

CyberSecurityUP

Hack
40
star
30

Web-PenTest-Checklist

40
star
31

Facial-Recognition-PenTest-Checklist

40
star
32

PenTest-Report-Collection

39
star
33

Windows-API-for-Red-Team

37
star
34

CyberSecurity-LinkedIn-Materials

34
star
35

Powershell-for-PenTest

27
star
36

Information-Security-Certifications-Map

26
star
37

AV-Bypass-codes

Python, C++ and Go
C++
20
star
38

Hackthebox-Privilege-Escalation

20
star
39

python-for-hackers

Python
19
star
40

Web-PenTest-Resume-Tips

19
star
41

Windows-Defender-DLL-Hijacking

C++
19
star
42

Osint-Social-Mapping

OSINT mapping using Twitter, Ficklr, Shodan and Insecam
Python
19
star
43

Fuxsociety

Fuxsociety Mr Robot 2.1
Python
18
star
44

Cybersecurity-Certifications-Guide

18
star
45

CRPYA

Challenge Python
Python
18
star
46

Bug-Bounty-Dorks-Vulns

16
star
47

Mitre-Attack-Matrix

16
star
48

Cracking-The-Perimeter-Framework

New Framework Red Team Operations
16
star
49

AWS-Cloud-Practicioner-Notes

15
star
50

Physical-PenTest-Methodology

Basic guide for performing a Physical PenTest - Nist 800-12, 800-53, 800-115, 800-152
15
star
51

shellcode-runner-rust

Simple Shellcode Runner in Rust Language
Rust
15
star
52

Cyber-Security-Contents

14
star
53

OSWP-Automated-tools

Shell
13
star
54

Python-Introduction

Python
13
star
55

Trevorfuscation

A tool that automates the trevorc2 powershell agent obfuscation process with the pyfuscation tool
Shell
12
star
56

backup-fu

Automatic cloud backup of Kali Linux data
Shell
11
star
57

Harden-Fu

Shell
11
star
58

HunterX

King of Bug Bounty Tips Simple Tool
Shell
11
star
59

Adversary-Emulation-Guide

11
star
60

k8senumeration

Kubernetes, Clusters and Dockers Enumeration in GCP and AWS environments
Python
11
star
61

C2Matrix-Automation

C2Matrix Automation
Shell
10
star
62

ISO-27002-Document

10
star
63

PyDorkGPT

Google Hacking using Prompt ChatGPT
Python
9
star
64

Ransomware-Codes

Educational repository with source code examples
9
star
65

LiesGate

C++
9
star
66

TTPs-Mitre-Attack

8
star
67

study-TI

Auxilios nos seus estudos e planejamento
6
star
68

Challenges

Challenge Inmetrics
HTML
6
star
69

AWS-Cloud-Architect-Associate-Notes

6
star
70

stalkfacebook1.0

Python
6
star
71

Documentation-of-information-security

6
star
72

Application-Vulnerable

6
star
73

Simple-Ransomwares

C++
6
star
74

Standards-and-Controls

5
star
75

RansomwarePy

Ransomware Python
Python
5
star
76

facebookstalking2.0

Python
5
star
77

block-website

Bloqueador de website feito em python
Python
5
star
78

Suicide-Prevention-Map

Suicide Prevention Map using Google Place API and Google Search API
Python
5
star
79

ReconFu

Scripts made in python to automate recognition
Python
5
star
80

shellcode-templates

Assembly
4
star
81

JWTK-Exploits

Python
4
star
82

Snake-AI

Edition Code for Python the AI
Python
4
star
83

owasp-asvs-checklist-portugues

4
star
84

reversescripts

Scripts para Engenharia Reversa
Python
4
star
85

CRTO-Study

Zeropoint Course CRTO
HTML
4
star
86

SafeBuddy

APK Suicide Prevention
Java
4
star
87

Gerador-de-Certificados

Fork de um projeto de Gerador de Certificados, deixo todos os crΓ©ditos ao dono
Python
4
star
88

Powershell-Wallpaper-Change

PowerShell
3
star
89

SilverEye-Twitter-Scraping

A tool created to scrape twitter using its own API
Python
3
star
90

MSFAutoVenom

Shell
3
star
91

OWASP-MSTG-PORTUGUESE

3
star
92

Asuna

Python
3
star
93

search-speech-recognition-basic

Python
3
star
94

Introdu-o-ao-Python-2

Python
3
star
95

My-CVEs

3
star
96

jscollect2

Python
3
star
97

ASUNA-basic

Python
3
star
98

JavaScript-Codigo-e-HTML

Course JavaScript
JavaScript
2
star
99

C2Automated

Python
2
star
100

First-Script-Meterpreter

Ruby
2
star