cognito-scanner

Cognito scanner

A tool for testing and exploiting weaknesses in AWS Cognito user authentication systems.

A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalation

GitHub

101 stars
2 watching
3 forks
Language: Python
last commit: over 2 years ago
Linked from 1 awesome list

auditcognitocybersecurityscannersecurity-tools

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
ncoblentz/burpmontoyacognitoA Java plugin for analyzing AWS Cognito requests and responses to identify potential vulnerabilities and exploit known issues7
capless/warrantA Python library for working with AWS Cognito user pools and supporting SRP authentication.471
aws-samples/amazon-cognito-developer-authentication-sampleDemonstrates developer-authenticated functionality of Amazon Cognito99
andresriancho/nimbostratusTools to discover vulnerabilities in Amazon cloud infrastructure448
edoardottt/cariddiA tool for crawling and scanning websites for sensitive information such as endpoints, secrets, and tokens.1,551
govtech-csg/paddingoraclehunterAn extension for Burp Suite to identify and exploit padding oracle vulnerabilities in cryptographic protocols.14
ekultek/zeus-scannerAn advanced reconnaissance utility designed to simplify web application reconnaissance964
cyberark/kubiscanAutomates the identification of risky permissions in Kubernetes clusters.1,329
mostaphabahadou/postenumAutomates system information gathering after gaining access to a Linux system.281
woj-ciech/kamerka-guiA tool designed to gather and analyze information about industrial control systems and other Internet of Things devices.724
rahulpsd18/cognito-backup-restoreA tool for backing up and restoring AWS Cognito User Pools197
shivangx01b/corsmeA tool to scan web applications for Cross-Origin Resource Sharing (CORS) misconfigurations.169
wafinfo/cobaltstrikeA plugin for Cobalt Strike that automates various tasks such as domain lookup, information gathering, and internal network scanning.179
edoardottt/cspreconTools for discovering new target domains using Content Security Policy385
tcosolutions/betterscanA toolchain that scans source code and infrastructure IaC for security risks and provides a unified report.831