Commit Graph

582 Commits

Author SHA1 Message Date
SirBroccoli
cccacb7ee1 Merge pull request #271 from HackTricks-wiki/update_Double_Agents__Exposing_Security_Blind_Spots_in_GC_20260331_131528
Double Agents Exposing Security Blind Spots in GCP Vertex AI
2026-04-07 14:27:51 +02:00
Carlos Polop
6b2c22a0f3 Normalize Vertex AI docs to enum/privesc/post-exploitation structure 2026-04-07 14:24:55 +02:00
SirBroccoli
941e8d69e6 Merge pull request #272 from HackTricks-wiki/update_Weaponizing_the_Protectors__TeamPCP_s_Multi-Stage__20260401_021730
Weaponizing the Protectors TeamPCP’s Multi-Stage Supply Chai...
2026-04-07 14:24:20 +02:00
Thomas Preece
a0ce4e47be Add new CodeBuild Credential leakage technique 2026-04-01 08:01:37 +01:00
HackTricks News Bot
9fe9a78f57 Add content from: Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Cha... 2026-04-01 02:22:22 +00:00
SirBroccoli
06110601f6 Merge pull request #269 from HackTricks-wiki/update_Full_Disclosure__A_Third__and_Fourth__Azure_Sign-I_20260319_185745
Full Disclosure A Third (and Fourth) Azure Sign-In Log Bypas...
2026-03-31 18:46:42 +02:00
HackTricks News Bot
f69b96a436 Add content from: Double Agents: Exposing Security Blind Spots in GCP Vertex A... 2026-03-31 13:21:35 +00:00
thug-gamer
5abaa4136c arte-leobalt - fix saml_forge.py script; fix typo 2026-03-31 11:36:49 +02:00
HackTricks News Bot
34568ac762 Add content from: Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypa... 2026-03-19 19:03:11 +00:00
SirBroccoli
126ea6644d Merge pull request #266 from HackTricks-wiki/update_How_to_detect_and_respond_to_OAuth_consent_attacks_20260304_184649
How to detect and respond to OAuth consent attacks in Google...
2026-03-17 19:42:55 +01:00
Bastian Kanbach
61f7d2a71b Update README.md
Updated URL of TeamsEnum Repository
2026-03-16 16:34:57 +01:00
Carlos Polop
6a9b95fe96 Add SEO post-processing for cloud wiki 2026-03-11 21:25:52 +01:00
HackTricks News Bot
028c5718bb Add content from: How to detect and respond to OAuth consent attacks in Google... 2026-03-04 18:49:07 +00:00
Carlos Polop
9e39e77d6e f 2026-03-04 12:21:21 +01:00
Carlos Polop
53d29a8805 Merge branch 'add-ad-entra-pivot-techniques' into master 2026-03-03 18:55:26 +01:00
Carlos Polop
36ea0d12e4 f 2026-03-03 18:53:49 +01:00
SirBroccoli
99f3c09476 Merge pull request #264 from HackTricks-wiki/update_ChatGPT_in_your_inbox__Investigating_Entra_apps_th_20260224_144948
ChatGPT in your inbox? Investigating Entra apps that request...
2026-03-03 16:32:28 +01:00
SirBroccoli
92afcc419d Update SUMMARY.md 2026-03-03 16:32:15 +01:00
Carlos Polop
8148555ca5 Remove outdated Connect Sync Policy Abuse technique 2026-03-03 00:49:59 +01:00
Carlos Polop
9bb45f07b4 Refine hybrid pivot docs with current exploitability status 2026-03-03 00:30:14 +01:00
chack
9c61bb2811 Add technical details for AD-to-Entra pivot techniques 2026-03-02 23:24:08 +00:00
chack
93c2d43192 Add AD to Entra pivot techniques from recent talk 2026-03-02 23:03:22 +00:00
Carlos Polop
9ebb2d956e f 2026-03-01 21:18:03 +01:00
Carlos Polop
d847f32cc5 f 2026-03-01 20:50:31 +01:00
Carlos Polop
0e45e2e2c7 Merge branch 'master' of github.com:HackTricks-wiki/hacktricks-cloud 2026-02-27 15:07:10 +01:00
Carlos Polop
d95f15f03e f 2026-02-27 15:07:09 +01:00
HackTricks News Bot
aa12679ea7 Add content from: ChatGPT in your inbox? Investigating Entra apps that request... 2026-02-24 14:49:51 +00:00
Marmeus
17397a0144 Fixed typos 2026-02-23 13:52:13 -05:00
Carlos Polop
202d0fe86c f robots 2026-02-23 11:53:26 +01:00
SirBroccoli
25552f6898 Merge pull request #260 from Marmeus/patch-1
Add command for EC2 console screenshot retrieval
2026-02-23 11:13:53 +01:00
Jaime Polop
a05e50758b Update gcp-storage-privesc.md 2026-02-23 11:11:37 +01:00
Jaime Polop
0cfe8fc87d Update README.md 2026-02-20 16:28:54 +01:00
Jaime Polop
633b608c29 Update README.md 2026-02-20 14:12:21 +01:00
Jaime Polop
005ab23773 Update README for IAM privilege escalation example 2026-02-20 14:10:28 +01:00
Marmeus
c35f2ca89b Add command for EC2 console screenshot retrieval
Added command to retrieve a JPG-format screenshot of a running instance.
2026-02-19 01:07:16 +00:00
SirBroccoli
1685887efa Merge pull request #259 from Tamirye/dataflowrider
grte-ye-ti
2026-02-16 12:06:38 +01:00
Carlos Polop
cd9939def6 f 2026-02-16 12:04:08 +01:00
Carlos Polop
fd262d744f f 2026-02-16 11:02:25 +01:00
Carlos Polop
0c445121d5 f 2026-02-15 22:17:38 +01:00
Tamir Yehuda
936fbc4285 added new GCP Dataflow exploitation, privilege escalation, and enumeration sections 2026-02-15 21:34:08 +02:00
Carlos Polop
3724e2729a f 2026-02-14 20:47:09 +01:00
Carlos Polop
616d1255a8 f 2026-02-14 17:54:58 +01:00
Carlos Polop
1829b6f80d f 2026-02-14 17:54:48 +01:00
Carlos Polop
967a945aa3 f 2026-02-14 15:50:33 +01:00
SirBroccoli
d5284abf61 Merge pull request #257 from AI-redteam/gcp-workstations-privesc
Gcp workstations privesc & container escape [grte-bstevens]
2026-02-12 20:36:18 +01:00
SirBroccoli
08ca5b601d Merge pull request #258 from AMOussama/bedrock-agentcore-code-interpreter
arte-Oussama - Bedrock agentcore code interpreter
2026-02-12 20:36:02 +01:00
Oussama Ait Manssour
4557349141 docs(aws): add AgentCore Code Interpreter role pivot privesc 2026-02-12 18:35:30 +01:00
Carlos Polop
745851f56d f ht url 2026-02-12 14:18:33 +01:00
SirBroccoli
d319c5283b Merge pull request #254 from HackTricks-wiki/update_GatewayToHeaven__Finding_a_Cross-Tenant_Vulnerabil_20260203_185749
GatewayToHeaven Finding a Cross-Tenant Vulnerability in GCP'...
2026-02-12 14:10:09 +01:00
Carlos Polop
9b923592af Move Apigee post-exploitation technique into its own page 2026-02-12 14:06:56 +01:00