awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेसMCP सर्वर
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
RhinoSecurityLabs avatar

RhinoSecurityLabs/pacu

0
View on GitHub↗
5,234 स्टार्स·788 फोर्क्स·Python·BSD-3-Clause·12 व्यूज़rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework↗

Pacu

Pacu एक एक्सप्लॉइटेशन फ्रेमवर्क है जिसे Amazon Web Services वातावरण की सुरक्षा का ऑडिट और परीक्षण करने के लिए डिज़ाइन किया गया है। यह क्लाउड पेनेट्रेशन टेस्टिंग टूल और संसाधन एन्यूमेरेटर के रूप में कार्य करता है जिसका उपयोग गलत कॉन्फ़िगरेशन की पहचान करने, अटैक सरफेस को मैप करने और विशेषाधिकार वृद्धि पथों को निष्पादित करने के लिए किया जाता है।

फ्रेमवर्क पोस्ट-एक्सप्लॉइटेशन और रेड टीम ऑपरेशंस के लिए विशेष क्षमताएं प्रदान करता है, जिसमें पहचान और एक्सेस प्रबंधन बैकडोरिंग के माध्यम से दृढ़ता स्थापित करना शामिल है। यह एक प्लगइन-आधारित मॉड्यूल सिस्टम के साथ खुद को अलग करता है जो कस्टम कार्यों के विकास और कई भौगोलिक क्षेत्रों में API अनुरोधों के ऑर्केस्ट्रेशन की अनुमति देता है।

यह प्रोजेक्ट सुरक्षा ऑडिटिंग गतिविधियों की एक विस्तृत श्रृंखला को कवर करता है, जिसमें बुनियादी ढांचे की गणना, भंडारण सेवाओं से डेटा निष्कर्षण और पहचान ऑडिटिंग शामिल है। इसमें पेलोड इंजेक्शन और स्टार्टअप स्क्रिप्ट के माध्यम से रिमोट कोड निष्पादन के लिए उपकरण शामिल हैं, साथ ही डिटेक्शन सेवाओं को बाधित करने और नेटवर्क पार्श्व आंदोलन का विश्लेषण करने की क्षमताएं भी शामिल हैं।

Pacu स्थिति बनाए रखने और API कॉल को कम करने के लिए अलग-थलग कंटेनरों और एक स्थानीय डेटाबेस का उपयोग करके लक्ष्य-विशिष्ट प्रमाणीकरण कुंजियों और सेशन मेटाडेटा का प्रबंधन करता है।

Features

  • Penetration Testing - Provides a comprehensive framework for conducting security assessments and penetration testing within AWS environments.
  • Cloud Privilege Escalation - Identifies and executes potential escalation paths by scanning for permission misconfigurations.
  • Lateral Movement - Identifies network connections to map lateral movement opportunities across the VPC.
  • Session State Persistence - Stores retrieved environment information in a local database to reduce API calls and track state across sessions.
  • Local Metadata Persistence - Maintains a local database of discovered security metadata and session state to minimize API calls.
  • AWS Resource-Type Enumeration Scanners - Enumerates AWS resource types by iterating through service APIs to map the overall environment footprint.
  • Tool Integration Plug-ins - Offers a plugin-based module system allowing developers to create custom exploitation and enumeration tasks using a standardized syntax.
  • ECS Resource Enumeration - Collects information on container clusters and parses their task definitions to map the attack surface.
  • AWS IAM Management - Enumerates all users, roles, groups, and customer-managed policies using AWS IAM APIs.
  • Persistence Mechanisms - Implements IAM user backdooring by adding unauthorized API keys or passwords to maintain long-term account persistence.
  • Cloud Security Assessors - Modifies cloud settings to identify configuration flaws and security vulnerabilities.
  • Cloud Resource Managers - Uses the Boto3 library to discover and control AWS virtual machines, storage, and network resources.
  • Cross-Region Orchestration - Iterates through cloud service endpoints across all available geographic regions using a central session manager.
  • Permission Enumerators - Searches enumerated permissions to find specific actions allowed on specific resources.
  • Bucket Data Exfiltration - Scans for accessible S3 buckets and downloads all contained files to a local directory.
  • Cloud Identity Enumerations - Identifies existing roles in remote accounts by analyzing responses to policy document update attempts.
  • Identity Backdoor Automation - Deploys functions and rules to automatically backdoor newly created roles or users.
  • Data Exfiltration Tools - Exfiltrates RDS data by creating snapshots of running databases and restoring them to new instances for access.
  • Cloud Service Data Exfiltration - Identifies and downloads sensitive data from S3 buckets, RDS snapshots, DynamoDB tables, and Secrets Manager.
  • Exploit Execution Engines - Executes specialized plugins to perform enumeration and data exfiltration against targeted cloud accounts.
  • Exploitation Frameworks - Serves as a platform for the development, testing, and execution of security exploits specifically for AWS.
  • Infrastructure Enumeration - Performs active infrastructure reconnaissance by collecting data on EC2 instances, security groups, and networks.
  • Permission Auditing Tools - Uses APIs to generate a confirmed list of permissions for users and roles.
  • Post-Exploitation Frameworks - Provides tools for managing access, maintaining persistence, and gathering data after an initial AWS account compromise.
  • IAM Policy Analyzers - Analyzes IAM policy evaluation paths to detect unintended permission chains and privilege escalation risks.
  • Cloud IAM Privilege Escalations - Scans for IAM misconfigurations and executes paths to increase access levels within an AWS environment.
  • Red Teaming Frameworks - Provides a toolkit of primitives for offensive security operations, adversary simulation, and persistence in AWS.
  • AWS Role Assumption - Establishes trust relationships between users and roles to allow unauthorized assumption of cloud identities.
  • AWS - Performs automated security checks of AWS resource settings and access controls to identify security gaps.
  • Penetration Testing Suites - Provides a suite of tools to automate security research and penetration testing tasks across cloud infrastructures.
  • Session Isolations - Isolates target-specific authentication keys and data into separate containers to manage multiple accounts.
  • Plugin-Based Architectures - Implements a plugin-based architecture to extend exploitation and enumeration capabilities via standalone scripts.
  • Downloads from Snapshots - Downloads specific EBS snapshots to a local machine for mounting and forensic exploration.
  • Snapshot Listings - Searches for EBS snapshots across multiple regions using keywords, account IDs, or wordlists.
  • Encryption Auditing - Lists database snapshots and identifies those that are unencrypted for security auditing.
  • Instance Attachments - Restores snapshots to volumes and attaches them to EC2 instances for detailed analysis.
  • Table Data Export - Enumerates DynamoDB tables and exports their values to local files for offline review.
  • Cloud Startup Script Injections - Injects custom shell scripts into instance startup data to run commands as root during reboot.
  • Enumeration - Enumerates available routes and methods to map existing API gateway infrastructure.
  • Template Data Extraction - Downloads templates and parameters from stacks to search for secrets.
  • Template Resource Injection - Injects administrative roles into templates via bucket notifications to gain access.
  • Cloud Organization Mapping - Enumerates organization entities and generates a visual tree of organizational units and accounts.
  • Security Group Backdoor Automation - Deploys functions and rules to automatically add rules to new security groups.
  • EKS Resource Enumeration - Lists and gathers information on managed Kubernetes cluster resources to map the attack surface.
  • IAM Policy Auditors - Analyzes IAM policies to discover valid users in remote accounts through targeted API interactions.
  • Enumeration - Enumerates and describes available message brokers to identify communication channels.
  • Zone Management - Lists hosted DNS zones and correlates them with query logging configurations.
  • Enumeration - Enumerates SFTP, FTP, and FTPS servers to identify available file transfer entry points.
  • Cloud Database Enumerations - Lists RDS database instances including master usernames, engines, ports, and endpoints.
  • Cloud Misconfiguration Discovery - Identifies EC2 instances that lack termination protection, exposing them to accidental or malicious deletion.
  • Cloud Security Account Mapping - Identifies master and linked security accounts to uncover lateral movement opportunities.
  • Container Image Backdoors - Injects malicious shell scripts into containers by modifying Docker images within task definitions.
  • Application Identity Management - Manages the lifecycle of active credentials by creating, swapping, and verifying identity permissions.
  • Cloud - Lists users, user pool clients, and identity pools within AWS Cognito.
  • Instance Metadata Extraction - Downloads the user data associated with specific instances or launch templates.
  • Cloud Identity Pool Exploits - Exploits AWS Cognito user and identity pool misconfigurations to escalate privileges.
  • Credential Metadata Retrieval - Retrieves identity details, user names, and associated permissions for the current active credentials.
  • CSV Formula Injections - Creates malicious resource identifiers that trigger formula execution when log exports are opened in spreadsheets.
  • Permission Brute Forcing - Identifies available permissions by attempting all possible API calls for supported services.
  • Security Group Backdooring - Adds ingress rules to security groups to allow access from a specific IP.
  • Secrets Extraction - Provides the ability to extract and decrypt parameters from the AWS Systems Manager Parameter Store across all regions.
  • Secrets Management - Enumerates and extracts secrets from the secrets manager and parameter store.
  • Finding Aggregators - Retrieves and aggregates security findings from threat detectors across the account.
  • Security Service Disruptions - Disables or deletes logging trails, security detectors, and flow logs to bypass detection.
  • Serverless Function Enumeration - Collects data on Lambda functions, including source code and policies, to identify misconfigurations.
  • Vulnerability Report Generation - Captures vulnerability findings from security inspector reports across supported regions.
  • Monitoring Service Discovery - Detects the presence of logging and monitoring services to evaluate the environment's visibility.
  • Remote Command Execution - Runs arbitrary commands with root or system privileges on virtual machines using remote command execution tools.
  • Cloud Security Tooling and Automation - AWS exploitation and penetration testing framework.
  • Cloud Infrastructure Security - Exploitation framework for testing AWS environment security.
  • Cloud Security - Exploitation framework for testing AWS security.
  • Cloud Security Auditing - Offensive security framework for testing AWS environments.
  • Offensive Security Tools - Comprehensive toolkit for AWS penetration testing.

स्टार हिस्ट्री

rhinosecuritylabs/pacu के लिए स्टार हिस्ट्री चार्टrhinosecuritylabs/pacu के लिए स्टार हिस्ट्री चार्ट

AI सर्च

और अधिक बेहतरीन रिपॉजिटरी खोजें

अपनी ज़रूरत को सरल भाषा में बताएं — AI हजारों क्यूरेटेड ओपन-सोर्स प्रोजेक्ट्स को प्रासंगिकता के आधार पर रैंक करता है।

Start searching with AI

Pacu के ओपन-सोर्स विकल्प

समान ओपन-सोर्स प्रोजेक्ट्स, जो Pacu के साथ साझा की गई सुविधाओं के आधार पर रैंक किए गए हैं।
  • byt3bl33d3r/crackmapexecbyt3bl33d3r का अवतार

    byt3bl33d3r/CrackMapExec

    9,144GitHub पर देखें↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Python
    GitHub पर देखें↗9,144
  • mantvydasb/redteaming-tactics-and-techniquesmantvydasb का अवतार

    mantvydasb/RedTeaming-Tactics-and-Techniques

    4,620GitHub पर देखें↗

    This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior. It serves as a comprehensive collection of technical guides and tactics for executing red team operations. The repository provides detailed instructions for Active Directory exploitation, including Kerberos abuse and domain privilege escalation. It covers defense evasion through API unhooking and payload obfuscation, as well as Windows internals research involving the manipulation of kernel objects and system memory. The capability surface extends to network penetration testi

    PowerShelloffensive-securityoscppentesting
    GitHub पर देखें↗4,620
  • samratashok/nishangsamratashok का अवतार

    samratashok/nishang

    9,951GitHub पर देखें↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    GitHub पर देखें↗9,951
  • rapid7/metasploit-frameworkrapid7 का अवतार

    rapid7/metasploit-framework

    38,415GitHub पर देखें↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    Rubyhacktoberfest
    GitHub पर देखें↗38,415
Pacu के सभी 30 विकल्प देखें→

अक्सर पूछे जाने वाले प्रश्न

rhinosecuritylabs/pacu क्या करता है?

Pacu एक एक्सप्लॉइटेशन फ्रेमवर्क है जिसे Amazon Web Services वातावरण की सुरक्षा का ऑडिट और परीक्षण करने के लिए डिज़ाइन किया गया है। यह क्लाउड पेनेट्रेशन टेस्टिंग टूल और संसाधन एन्यूमेरेटर के रूप में कार्य करता है जिसका उपयोग गलत कॉन्फ़िगरेशन की पहचान करने, अटैक सरफेस को मैप करने और विशेषाधिकार वृद्धि पथों को निष्पादित करने के लिए किया जाता है।

rhinosecuritylabs/pacu की मुख्य विशेषताएं क्या हैं?

rhinosecuritylabs/pacu की मुख्य विशेषताएं हैं: Penetration Testing, Cloud Privilege Escalation, Lateral Movement, Session State Persistence, Local Metadata Persistence, AWS Resource-Type Enumeration Scanners, Tool Integration Plug-ins, ECS Resource Enumeration।

rhinosecuritylabs/pacu के कुछ ओपन-सोर्स विकल्प क्या हैं?

rhinosecuritylabs/pacu के ओपन-सोर्स विकल्पों में शामिल हैं: byt3bl33d3r/crackmapexec — CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security… mantvydasb/redteaming-tactics-and-techniques — This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior.… samratashok/nishang — Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows… rapid7/metasploit-framework — The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of… byt3bl33d3r/offensivenim — OffensiveNim is a red teaming framework and post-exploitation toolkit developed in Nim. It provides a collection of… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities…