Skip to content

Repository files navigation

Cloud Security Toolkit

The Art of Cloud Exploitation

Welcome to the Cloud Security Toolkit—a specialized resource designed for offensive security researchers, red teamers, and adversaries. This repository is dedicated to the systematic weaponization of vulnerabilities, advanced attack simulations, and the breakdown of defense mechanisms across the cloud ecosystem.

Note: This repository is actively evolving. Exploits, attack scripts, payload libraries, and offensive KQL queries are continuously integrated. Stay sharp.

Inside the Armory ⚔️

Equip your red team engagements with mission-critical resources:

Every component in this toolkit is battle-hardened, extracted from high-stakes penetration tests, red team operations, and vulnerability research. This is where theory meets the metal.

Targeted Ecosystems 🎯

  • 🆔 Entra ID & M365: Identity theft, token theft, and tenant takeover.
  • ☁️ Azure & AWS: Infrastructure exploitation, IAM abuse, and container escapes.
  • 🛡️ Defense Evasion: Blinding Sentinel and neutering Defender XDR.
  • 🌪️ Multi-Cloud Supremacy: Cross-platform attack chains.

Stay lethal and keep hunting. 🌐🔥

Every piece of content here is battle-tested, drawn from real-world incident responses (IR), cloud penetration tests (PT), security assessments, and more. This is practical knowledge, not just theory!

In addition to the core resources, this repo features tools and scripts specifically designed for:

  • 🛡️ Microsoft Sentinel
  • 🔐 Microsoft Defender XDR
  • 🆔 Entra ID
  • 🔍 Azure Security
  • 🔒 Multi-Cloud Security (Microsoft 365, Azure, AWS, GCP, GWS)
  • 🌟 And other essential cloud security tools

Stay secure and happy exploring! 🌐🔐

Note: This Hub replaces the Microsoft-Sentinel-SecOps repo. The content from the Microsoft-Sentinel-SecOps repo is being migrated to this new repository.

About

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing vulnerabilities and simulating advanced attacks across Azure, Entra ID, AWS, and M365.

Topics

Resources

Security policy

Stars

29 stars

Watchers

1 watching

Forks

Used by

Contributors

Languages