Tool · cloud-securitypassive
Monkey365
An open-source PowerShell security assessment framework for Microsoft 365, Azure, and Entra ID that identifies misconfigurations and evaluates cloud posture against CIS benchmarks. Covers workloads like Exchange Online, SharePoint, Teams and Purview, supports multiple auth methods and national clouds, and exports HTML/JSON/CSV reports.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
More tools
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.
- AI Vuln Scannerdast/web-app-scannerA security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.
- Aktoapi-securityOpen-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.
- AmassreconDeep passive subdomain enumeration across many public sources.
- ArjundiscoveryDiscovers hidden HTTP parameters using a bundled (SecLists-upsizable) wordlist.
- assetfinderreconFast passive subdomain discovery drawing on crt.sh, certspotter, hackertarget, threatcrowd and wayback.