BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and configurable, traversable attack paths.
-
Updated
Aug 27, 2026 - Python
BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and configurable, traversable attack paths.
Salesforce identity and permission graph collector for BloodHound CE. Maps users, profiles, permission sets, roles, groups, sharing rules, connected apps, and field-level security into attack-path graphs.
GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted objects via SHOW_DELETED, mapping who can restore them, and revealing when a reanimated identity regains privileged group membership.
The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber risk through the elimination of attack paths.
browser-based Active Directory attack graph tool for SharpHound and AzureHound collection data. No server. No install. No Neo4j. Upload a ZIP, get an interactive attack graph.
Offline-first threat modeling and architecture diagram editor with AI-powered security analysis, MITRE ATT&CK/NIST mapping, local Ollama support, and integrated GRC attack-path workflows.
Finds the reachable paths from internet exposure, through excessive privilege, to a sensitive asset, by correlating the scanners you already run into one live graph of your environment. Flags them in the pull request that opens them and ships the fix as a PR. Open source, Apache-2.0.
Python CLI for offensive-focused Azure situational awareness and management-plane reconnaissance.
BloodHound for AI agents — visualize attack paths through MCP tool chains
This is local defensive security toolkit with scanner, recon, honeypots, vulnerability correlation, evidence graph, attack path ranking, and reports.
Go CLI for attack-path-focused Azure reconnaissance, pivot analysis, and management-plane cloud security workflows.
Active Directory Attack Path Discovery Mapper — LDAP enumeration, privilege escalation analysis, and MITRE ATT&CK mapped remediation
Prove whether an internet-to-database attack path exists in your Terraform — before you apply.
Cross-tool correlation engine for the Entra ID security suite — joins findings across three scanners to surface risks no single tool detects.
Map AWS IAM permissions into a Neo4j graph for visual analysis
HarrierOps Kube - offensive-focused Kubernetes recon and chaining CLI
AI-Powered Active Directory Attack Path Analysis with BloodHound - By Ayi NEDJIMI
Build reproducible cloud Cyber-Range Mazes with randomly selected CVEs for benchmarking Security Agents and RAG-assisted Attack-Path Research.
Explainable GCP IAM authorization and attack-path analyzer with inherited deny policies, three-state decisions, SARIF reporting, and CI.
Real-time cloud attack path prediction and simulation
To associate your repository with the attack-path topic, visit your repo's landing page and select "manage topics."