This is your work, valued

Cloud

Chandrapal Badshah

Elite
@0xbadshah

Vibe Security Researcher

Awesome-MitM. Curated List of MitM frameworks on GitHub

258

WinHotspot. A free open source python program to start WiFi hotspot in Windows without any external software

27

aws-mfa-enforce. Serverless function to automate enforcement of Multi-Factor Authentication (MFA) to all AWS IAM users with access to AWS Management Console.

13

owasp-mstg. The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security development, testing and reverse engineering.

4

hacks. Go

4

Dependabot-Dashboard. Python

4

changeme. A default credential scanner.

4

owasp-workshop-android-pentest. Learning Penetration Testing of Android Applications

3

Best-Penetration-Tools-. Best Penetration Tools | أفضل أدوات الاختراق

3

aws-summarize-account-activity. Analyzes CloudTrail data of a given AWS account and generates a summary of recently active IAM principals, API calls they made, as well as regions, IP addresses and user agents they used.

3

OSINT-SPY. Performs OSINT scan on email/domain/ip_address/organization using OSINT-SPY. It can be used by Data Miners, Infosec Researchers, Penetration Testers and cyber crime investigator in order to find deep information about their target. If you want to ask something please feel free to reach out to me at sharadkumar98780@gmail.com

3

0xbadshah.

3

Awesome-Black-Friday-Cyber-Monday. Awesome deals on Black Friday: Apps, SaaS, Books, Courses, etc.

2

GCP-pentest-lab. A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities

2

awesome-web-security. 🐶 A curated list of Web Security materials and resources.

2

metasploitable3. Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

2

OSINTforPenTests. Slides from my ShellCon Talk, OSINT for Pen Tests, given 10/19.

2

puppeteer-lambda-starter-kit. Starter Kit for running Headless-Chrome by Puppeteer on AWS Lambda.

2

IntRec-Pack. Intelligence and Reconnaissance Package/Bundle installer.

2

go-pillage-registries. Pentester-focused Docker registry tool to enumerate and pull images

2

bXSS. bXSS is a simple Blind XSS application adapted from https://cure53.de/m

2

get_schemas. Print out URL schemas from an Android app

2

Awesome-Asset-Discovery. List of Awesome Asset Discovery Resources

2

spiderfoot. SpiderFoot, the open source footprinting and intelligence-gathering tool.

2

ansible-lemp-wp-certbot-playbook. Ansible playbook to deploy a static html, php, php+mysql or wordpress website with Let's Encrypt SSL/TLS certificate

2

local-sheriff. Think of Local sheriff as a recon tool in your browser (WebExtension). While you normally browse the internet, Local Sheriff works in the background to empower you in identifying what data points (PII) are being shared / leaked to which all third-parties.

2

Proxy-List. Python program to check accessible proxy sites

2

WIZwiki-W7500.

2

shhgit. Find GitHub secrets in real time

2

003Recon. Some tools to automate recon - 003random

2

blackhat-arsenal-tools. Official Black Hat Arsenal Security Tools Repository

2

vuls. Agent-less vulnerability scanner for Linux/FreeBSD/WordPress/Programming language libraries/Network devices

2

InfoSec-Black-Friday. All the deals for InfoSec related software/tools this Black Friday

1

prowler. Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.

1

testing-devcontainer. Python

1

my-arsenal-of-aws-security-tools. List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

1

codeql-javascript-unsafe-jquery-plugin. CodeQL

1

ctfhub. Some Docker for CTF environments

1

NativePayload_DNS2. C# code for transferring Backdoor Payloads by DNS Traffic (A Records) and Bypassing Anti-viruses

1

Kotlin. Sample Android apps I made to learn Kotlin

1

proctor-helm-charts. Smarty

1

serverless_toolkit. A collection of useful Serverless functions I use when pentesting

1

protobuf-decoder. A simple Google Protobuf Decoder for Burp

1

Gorsair. Gorsair hacks its way into remote docker containers that expose their APIs.

1

android-binaries. Binaries compiled for ARM

1