All resources
Topic

cloud

4 resources across 2 kinds

Tools

  1. GraphSpyactivehigh-risk

    A browser-based tool for authorized post-compromise operations against Microsoft 365 and Entra ID: it stores and switches between access/refresh tokens and Primary Refresh Tokens, runs device-code flows, browses OneDrive/SharePoint/Outlook/Teams data, enumerates users and roles, and issues arbitrary Microsoft Graph requests. It also supports adding MFA methods (TOTP, FIDO, phone) for account persistence.

    Open ↗
  2. Pacuactivehigh-risk

    An open-source AWS exploitation framework by Rhino Security Labs with a modular architecture for enumeration, privilege escalation, IAM user backdooring, Lambda exploitation, lateral movement, data exfiltration, and log manipulation. It tracks enumerated data in a local SQLite database and logs commands for audit trails.

    Open ↗
  3. AzureHoundactivelicence

    SpecterOps's Go data collector that enumerates Microsoft Azure/Entra tenant data and formats it for BloodHound to map attack paths and privilege-escalation routes. It supports multiple auth methods (username/password, JWT, refresh tokens, Azure CLI), runs as a CLI or persistent service, and ships cross-platform binaries.

    Open ↗

Labs & practice targets

  1. CloudGoatcloud costhosted

    Rhino Security Labs' 'vulnerable by design' AWS/Azure deployment tool with CTF-style cloud attack scenarios.

    Open ↗