XRayC2 shows how AWS X-Ray can be abused as a covert command and control channel. Practical walkthrough, install, attack scenario, detections.
Cloud Security
CloudConqueror – AWS CloudControl API Attack Surface Mapping and Persistence Tool
CloudConqueror maps and abuses the AWS CloudControl API for discovery, resource enumeration, and persistence. Learn how attackers and defenders can test detection coverage and harden cloud environments.
IAMhounddog – Practical AWS IAM Relationship Mapping for Red Teams
IAMhounddog maps AWS IAM relationships to reveal privilege escalation chains. Hands-on walk-through, graph export and detection guidance for red teams.
TagNabIt – AWS Cloud Resource Enumeration via Metadata Tags
TagNabIt is an offensive security tool for enumerating cloud resources through metadata tags, exposing overlooked attack surfaces in modern environments.
AzureStrike – Offensive Toolkit for Attacking Azure Active Directory Environments
AzureStrike is a red team toolkit for attacking Azure Active Directory, enabling reconnaissance, credential abuse, and persistence in cloud environments.
Veles – Google’s Open Source Secret Scanner for GCP Key Detection
Google releases Veles, a lightweight open-source secret scanner for GCP credentials, now integrated with OSV-SCALIBR and deps.dev.
Envilder – Secure AWS SSM CLI for Environment Variable Management
Envilder is a fast, secure CLI tool that syncs environment variables from AWS SSM Parameter Store to your local shell or .env files, ideal for secrets and config hygiene.
Monkey365 – PowerShell Security Scanner for Microsoft 365, Azure, and Entra ID
Monkey365 is an open-source PowerShell scanner that automates security and compliance reviews across Microsoft 365, Azure subscriptions, and Entra ID. No dashboards or cloud APIs required.








