Azure-DevOps-server-supply-chain-attack-tree

Attack model

An attack tree model for identifying potential security vulnerabilities in an Azure DevOps Server supply chain.

Azure DevOps server supply-chain attack tree (map, Attack surface, threat modeling)

GitHub

7 stars
2 watching
3 forks
last commit: over 3 years ago
attack-treeattack-treesazure-devopsazure-devops-serversupply-chain

Related projects:

RepositoryDescriptionStars
sbasu7241/aws-threat-simulation-and-detectionThis repository documents the simulation and detection of various AWS attack scenarios using Stratus Red Team and SumoLogic for logging and analysis.284
azure/simulandA collaboration to create realistic test environments for simulating real-world attacks and improving detection strategies.704
chong-z/tree-ensemble-attackAn approach to create adversarial examples for tree-based ensemble models22
azure/stormspotterA tool for analyzing and visualizing Azure objects to help security teams understand potential attack surfaces.1,555
stevespringett/threatmodel-sdkA Java library for parsing and using threat model data in a standardized way79
devsecops/raindanceA framework to simplify attack mapping and security modeling in software development46
jlopp/physical-bitcoin-attacksCompiles known physical attacks on Bitcoin and cryptocurrency owners583
lightspin-tech/lightspin-2022-top-7-attack-pathsCompiles research on cloud security trends and attack paths39
indeedops/shadowbusterAn attack mapping application that visualizes real-time events and pushes them to the front end via websockets.80
r3dxpl0it/cve-2018-4407Exploits a heap buffer overflow vulnerability in the XNU operating system kernel to cause a denial-of-service attack on iOS and macOS devices.35
attackercan/burp-xss-sql-pluginAutomated tool for detecting cross-site scripting (XSS) and SQL injection vulnerabilities in web applications.44
trustoncloud/threatmodel-for-aws-s3An inventory of common attack scenarios on Amazon S3 storage and recommended countermeasures151
cloud-architekt/azuread-attack-defenseA collection of attack scenarios and mitigation strategies for Microsoft Entra ID2,183
voulnet/barqAn AWS-focused post-exploitation framework that enables attackers to compromise running EC2 instances without needing original credentials.386
tomac/yersiniaA framework for creating Layer 2 attacks to disrupt Spanning Tree protocols.732