BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and configurable, traversable attack paths.
-
Updated
Aug 6, 2026 - Python
BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and configurable, traversable attack paths.
Salesforce identity and permission graph collector for BloodHound CE. Maps users, profiles, permission sets, roles, groups, sharing rules, connected apps, and field-level security into attack-path graphs.
Python CLI for offensive-focused Azure situational awareness and management-plane reconnaissance.
BloodHound for AI agents — visualize attack paths through MCP tool chains
This is local defensive security toolkit with scanner, recon, honeypots, vulnerability correlation, evidence graph, attack path ranking, and reports.
AI-Powered Active Directory Attack Path Analysis with BloodHound - By Ayi NEDJIMI
Prove whether an internet-to-database attack path exists in your Terraform — before you apply.
Context-aware vulnerability prioritization with attack-path chaining. Self-hosted, no lock-in, swap any scanner.
Real-time cloud attack path prediction and simulation
Compute an Entra ID identity's blast radius: everything it can reach - roles, nested groups, PIM-eligible, owned apps - ranked worst-first.
Desktop Active Directory Attack Path Analysis Platform for Security Risk Assessment and MITRE ATT&CK Mapping
Automated detection of privilege escalation paths in Microsoft Entra ID
Transforms BloodHound attack paths into attacker capability analysis, privilege escalation reasoning, and operator-focused walkthroughs.
A network security tool that analyzes hosts from an Nmap scan or YAML inventory, classifies them by role and sensitivity, and generates a least-privilege segmentation plan. It creates security zones, justified firewall rules, and compares attack paths before and after segmentation to show reduced lateral movement.
AI-powered attack path synthesizer with cross-tool integration — ingest findings from 45+ tools, build knowledge graphs, and synthesize realistic attack paths with MITRE ATT&CK mappings
IaC blast radius analyzer for Terraform and Kubernetes. Parses HCL/YAML, builds a NetworkX dependency graph, detects CIS benchmark violations via local RAG, performs multi-hop chain reasoning to discover attack paths, generates LLM attack narratives, and ranks fixes by impact.
🧵 Offline, deterministic attack-path decision engine — turns nmap/gobuster/masscan output into prioritized, reasoned next steps. 208 rules, interactive console, zero dependencies.
Automated detection of privilege escalation paths in AWS IAM
Build reproducible cloud Cyber-Range Mazes with randomly selected CVEs for benchmarking Security Agents and RAG-assisted Attack-Path Research.
Add a description, image, and links to the attack-path topic page so that developers can more easily learn about it.
To associate your repository with the attack-path topic, visit your repo's landing page and select "manage topics."