kpawloski's Stars
aws-samples/data-perimeter-policy-examples
Example policies demonstrating how to implement a data perimeter on AWS.
SummitRoute/aws_breaking_changes
List of changes announced for AWS that may break existing code
WithSecureLabs/IAMGraph
robchahin/sso-wall-of-shame
A list of vendors that treat single sign-on as a luxury feature, not a core security requirement.
ipinfo/cli
Official Command Line Interface for the IPinfo API (IP geolocation and other types of IP data)
salesforce/aws-allowlister
Automatically compile an AWS Service Control Policy that ONLY allows AWS services that are compliant with your preferred compliance frameworks.
dmuth/aws-s3-server-access-logging-rollup
A Python script to perform regular rollup of AWS S3 Server Access Logs
aws-samples/aws-secure-environment-accelerator
The AWS Secure Environment Accelerator is a tool designed to help deploy and operate secure multi-account, multi-region AWS environments on an ongoing basis. The power of the solution is the configuration file which enables the completely automated deployment of customizable architectures within AWS without changing a single line of code.
someengineering/fixinventory
Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.
zusorio/GoodTwitter
priyankavergadia/google-cloud-4-words
The Google Cloud Developer's Cheat Sheet
usingnamespace/pyramid_authsanity
An auth policy for the Pyramid Web Framework with sane defaults.
getsops/sops
Simple and flexible tool for managing secrets
duo-labs/cloudmapper
CloudMapper helps you analyze your Amazon Web Services (AWS) environments.
Netflix/security_monkey
Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.
SpecterOps/BloodHound-Legacy
Six Degrees of Domain Admin
commixproject/commix
Automated All-in-One OS Command Injection Exploitation Tool.
jvoisin/php-malware-finder
Detect potentially malicious PHP files
elceef/dnstwist
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
carmaa/inception
Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard, PC Card and any other PCI/PCIe interfaces.
gentilkiwi/mimikatz
A little tool to play with Windows security
ossec/ossec-hids
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
mothran/tlslite
TLS Library in python
wpscanteam/wpscan
WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com
sqlmapproject/sqlmap
Automatic SQL injection and database takeover tool
PowerShellMafia/PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework
lucab/ntop