| 2025-12-10 | Tool demo | Blackhat |
EKSi-lite: Simple & Lightweight EKS Cluster Listing & Security Tool
| Divyanshu Shukla, Anjali Singh Shukla | #aws#kubernetes#cloud-security-posture-management+4 |
| 2025-12-10 | Tool demo | Blackhat |
Kubernetes Goat β A Hands-on Interactive Kubernetes Security Playground
| Madhu Akula | #kubernetes#container-security#cloud-pentesting+1 |
| 2025-12-10 | Tool demo | Blackhat |
KubeShadow - Advanced Offensive Kubernetes Red-Team Framework
| Aashita Pandey, Binayak Choudhury | #kubernetes#red-teaming#cloud-pentesting+1 |
| 2025-08-07 | Tool demo | Blackhat |
Cloud Offensive Breach and Risk Assessment (COBRA)
| Harsha Koushik, Anand Tiwari | #cloud-pentesting#risk-management#edr |
| 2025-08-07 | Tool demo | Blackhat |
Halberd : Multi-Cloud Agentic Attack Tool
| Arpan Abani Sarkar | #cloud-access-security-broker#cloud-pentesting#security-testing+3 |
| 2025-08-07 | Talk | Blackhat |
Kernel-Enforced DNS Exfiltration Security: Framework Built for Cloud Environments to Stop Data Breaches via DNS at Scale
| Vedang Parasnis | #dns#data-leak#kernel+1 |
| 2025-08-06 | Tool demo | Blackhat |
CloudLens
| Gaurav Joshi, Hare Krishna Rai, K v Prashant | #aws#cloud-pentesting#red-teaming+2 |
| 2025-08-06 | Tool demo | Blackhat |
RedInfraCraft : Automate Complex Red Team Infra
| Yash Bharadwaj, Manish Gupta | #red-teaming#cloud-access-security-broker#cloud-compliance+4 |
| 2025-06-27 | Talk | Lehack |
From HTML Injection to Full AWS Account Takeover: Discovering Critical Risks in PDF Generation
| Raunak Parmar | #ssrf#aws#web-security+2 |
| 2025-04-04 | Tool demo | Blackhat |
Agneyastra - Firebase Misconfiguration Detection Toolkit V2
| Bhavarth Karmarkar, Devang Solanki | #misconfiguration#cloud-pentesting#security-tools+1 |
| 2025-04-04 | Tool demo | Blackhat |
Kubernetes Goat: A Hands-on Interactive Kubernetes Security Playground
| Madhu Akula | #kubernetes#cloud-workload-protection#container-security+4 |
| 2025-04-04 | Tool demo | Blackhat |
RedInfraCraft : Automate Complex Red Team Infra
| Yash Bharadwaj, Manish Gupta | #cloud-access-security-broker#cloud-compliance#cloud-pentesting+1 |
| 2025-04-03 | Tool demo | Blackhat |
Halberd : Multi-Cloud Security Testing Tool
| Arpan Abani Sarkar | #cloud-access-security-broker#cloud-pentesting#security-tools+2 |
| 2025-03-02 | Talk | Nullcon |
Kernel Conquest: Breaking Boundaries and Demystifying Kernel SU for Root Access in Azure Cloud Shell
| Alla Vamsi Krishna, Kandi Abhishek Reddy | #kernel#azure#container-security+2 |
| 2024-12-12 | Tool demo | Blackhat |
Cloud Offensive Breach and Risk Assessment (COBRA)
| Harsha Koushik, Anand Tiwari | #cloud-pentesting#cloud-workload-protection#security-testing+3 |
| 2024-12-12 | Tool demo | Blackhat |
GoatPen: Hack, Hone, Harden
| Nishant Sharma, Shantanu Kale | #aws#cloud-access-security-broker#cloud-compliance+4 |
| 2024-12-12 | Tool demo | Blackhat |
Halberd : Cloud Security Testing Tool
| Arpan Abani Sarkar | #cloud-pentesting#red-teaming#azure+1 |
| 2024-12-12 | Tool demo | Blackhat |
RedCloud OS : Cloud Adversary Simulation Operating System
| Yash Bharadwaj, Manish Gupta | #cloud-pentesting#red-teaming#aws+1 |
| 2024-12-11 | Tool demo | Blackhat |
Agneyastra - Firebase Misconfiguration Detection Toolkit
| Bhavarth Karmarkar, Devang Solanki | #cloud-pentesting#misconfiguration#bug-bounty |
| 2024-12-11 | Tool demo | Blackhat |
findmytakeover - find dangling domains in a multi cloud environment
| Aniruddha Biyani | #dns#cloud-pentesting#reconnaissance |
| 2024-10-02 | Talk | Virusbulletin |
From code to crime: exploring threats in GitHub Codespaces
| Nitesh Surana, Jaromir Horejsi | #cloud-pentesting#supply-chain-security#exploitation |
| 2024-08-08 | Tool demo | Blackhat |
Cloud Offensive Breach and Risk Assessment (COBRA)
| Anand Tiwari, Harsha Koushik | #cloud-security-posture-management#cloud-pentesting#security-testing+1 |
| 2024-08-07 | Tool demo | Blackhat |
BucketLoot - An Automated S3 Bucket Inspector
| Kunal Aggarwal, Umair Nehri | #aws#cloud-pentesting#reconnaissance+1 |
| 2024-08-07 | Tool demo | Blackhat |
RedCloud OS : Cloud Adversary Simulation Operating System
| Manish Gupta, Yash Bharadwaj | #os#cloud-pentesting#aws+4 |
| 2024-05-27 | Talk | Confidence |
Hacker’s Story from Reader to Global Admin in Azure
| Raunak Parmar | #cloud-pentesting#azure#ethical-hacking+4 |
| 2024-05-24 | Talk | Auscert |
Mastering the art of Attacking and Defending a Kubernetes Cluster
| Sanjeev Mahajan | #kubernetes#cloud-pentesting#container-security+1 |
| 2024-04-19 | Tool demo | Blackhat |
AWSDefenderGPT: Leveraging OpenAI to Secure AWS Cloud
| Sherin Stephen, Nishant Sharma, Rishappreet Singh Moonga | #aws#ai-security#ai+4 |
| 2024-04-19 | Tool demo | Blackhat |
BucketLoot - An Automated S3 Bucket Inspector
| Umair Nehri | #aws#cloud-pentesting#reconnaissance+1 |
| 2024-04-18 | Talk | Blackhat |
Breaking Managed Identity Barriers In Azure Services
| Nitesh Surana, David Fiser | #azure#cloud-pentesting#access-management+3 |
| 2024-04-18 | Tool demo | Blackhat |
Catching adversaries on Azure - Deception on Cloud
| Subhash Popuri | #azure#cloud-workload-protection#cloud-pentesting+4 |
| 2024-04-18 | Tool demo | Blackhat |
findmytakeover - find dangling domains in a multi cloud environment
| Aniruddha Biyani | #dns#cloud-workload-protection#cloud-pentesting+1 |
| 2024-04-18 | Tool demo | Blackhat |
Nightingale: Docker for Pentesters
| Raja Nagori | #docker#application-pentesting#cloud-pentesting+3 |
| 2024-04-18 | Tool demo | Blackhat |
RedCloud OS : Cloud Adversary Simulation Operating System
| Manish Gupta, Yash Bharadwaj | #os#cloud-pentesting#aws+4 |
| 2023-12-07 | Tool demo | Blackhat |
Route53Sweep: Empowering AWS Route53 Security with Automated Scanning & Comprehensive Inventory Management
| Divyanshu Shukla, Anjali Singh Shukla | #aws#cloud-access-security-broker#cloud-monitoring+2 |
| 2023-12-06 | Tool demo | Blackhat |
BucketLoot - An Automated S3-compatible Bucket Inspector
| Owais Shaikh, Umair Nehri | #aws#cloud-pentesting#reconnaissance+1 |
| 2023-12-06 | Tool demo | Blackhat |
Docker Exploitation Framework
| Rohit Pitke, Emmanuel Law | #exploitation#container-security#docker+4 |
| 2023-12-06 | Tool demo | Blackhat |
HAWK Eye - PII & Secret Detection tool for your Servers, Database, Filesystems, Cloud Storage Services
| Rohit Kumar | #bug-hunting#data-loss-prevention#data-protection+4 |
| 2023-09-28 | Talk | Rootcon |
Azure Illuminati: Unveiling the Mysteries of Cloud Exploitation
| Raunak Parmar | #azure#cloud-pentesting#mfa+4 |
| 2023-09-23 | Talk | Nullcon |
Uncovering Azure’s Silent Threats: A Journey Into Cloud Vulnerabilities
| Nitesh Surana | #azure#cloud-pentesting#application-hardening+4 |
| 2023-08-25 | Talk | Hitbsecconf |
Breaking ML Services: Finding 0-days in Azure Machine Learning
| Nitesh Surana | #machine-learning#cloud-access-security-broker#cloud-compliance+4 |
| 2023-08-24 | Tool demo | Hitbsecconf |
Vajra
| Raunak Parmar | #aws#azure#cloud-pentesting+3 |
| 2023-08-10 | Talk | Blackhat |
Uncovering Azure’s Silent Threats: A Journey into Cloud Vulnerabilities
| Nitesh Surana, Magno Logan, David Fiser | #azure#cloud-pentesting#cloud-vulnerabilities+1 |
| 2023-08-09 | Tool demo | Blackhat |
BucketLoot - An Automated S3 Bucket Inspector
| Owais Shaikh, Umair Nehri | #aws#cloud-pentesting#reconnaissance+1 |
| 2023-08-09 | Tool demo | Blackhat |
DIAL - Did I Alert Lambda? Centralised Security Misconfiguration Detection Framework
| Saransh Rana, Rashid Feroze, Harsh Varagiya | #misconfiguration#cloud-access-security-broker#cloud-monitoring+4 |
| 2023-08-07 | Talk | C0c0n |
Cyber Threats to Global Financial Systems
| Lince Lawrence | #incident-management#risk-management#cloud-monitoring+4 |
| 2023-08-07 | Talk | C0c0n |
Serverless Siege: AWS Lambda Pentesting
| Anjali Singh Shukla, Divyanshu Shukla | #aws#serverless#cloud-pentesting+2 |
| 2023-08-07 | Talk | C0c0n |
Uncovering Azure’s Silent Threats: A Story of Cloud Vulnerabilities
| Nitesh Surana | #azure#cloud-vulnerabilities#cloud-pentesting+1 |
| 2023-06-01 | Talk | Securityfest |
Beyond On-Premises: Exploring the Post-Domain Admin Landscape in the Cloud
| Sriraam Natarajan, Venkatraman Kumar | #red-teaming#azure#active-directory+2 |
| 2023-05-12 | Tool demo | Blackhat |
GCPGoat : A Damn Vulnerable GCP Infrastructure
| Shantanu Kale, Rishappreet Singh Moonga, Ravi Verma, Govind Krishna | #gcp#cloud-pentesting#cloud-workload-protection+4 |
| 2023-05-12 | Tool demo | Blackhat |
Vajra - Your Weapon To Cloud
| Raunak Parmar | #aws#azure#cloud-pentesting+4 |
| 2023-05-11 | Tool demo | Blackhat |
AzureGoat : A Damn Vulnerable Azure Infrastructure
| Nishant Sharma, Dasari Yashwanth Babu | #azure#cloud-pentesting#cloud-workload-protection+2 |
| 2023-05-11 | Tool demo | Blackhat |
Kubernetes Goat: Interactive Kubernetes Security Learning Playground
| Madhu Akula | #kubernetes#cloud-workload-protection#container-security+4 |
| 2022-12-08 | Tool demo | Blackhat |
ThunderCloud: Attack Cloud Without Keys!
| Shivankar Madaan | #aws#azure#gcp+2 |
| 2022-09-28 | Talk | Rootcon |
AWSGoat : A Damn Vulnerable AWS Infrastructure
| Jeswin Mathai, Shantanu Kale, Sanjeev Mahunta | #aws#cloud-pentesting#cloud-workload-protection+4 |
| 2022-09-23 | Talk | C0c0n |
A Tale of Credential Leak of a Popular Cloud Threat Actor
| Nitesh Surana | #security-assessment#cloud-pentesting#cloud-workload-protection+2 |
| 2022-09-23 | Talk | C0c0n |
Common Misconfigurations in your Kubernetes Cluster and What can you do about it?
| Kumar Ashwin | #kubernetes#cloud-workload-protection#container-security+4 |
| 2022-09-08 | Talk | Nullcon |
Handling A Bug Bounty program From A Blue Team Perspective
| Ashwath Kumar, Ankit Anurag | #blueteam#cloud-monitoring#cloud-pentesting+4 |
| 2022-09-08 | Tool demo | Nullcon |
Vajra - Your Weapon To Cloud
| Raunak Parmar | #cloud-security-posture-management#cloud-pentesting#azure+4 |
| 2022-09-07 | Talk | Nullcon |
Scale hacking to secure your cloud and beyond
| Anand Prakash | #cloud-pentesting#cloud-security-posture-management#container-security+4 |
| 2022-08-10 | Tool demo | Blackhat |
AWSGoat : A Damn Vulnerable AWS Infrastructure
| Nishant Sharma, Jeswin Mathai, Sanjeev Mahunta | #aws#cloud-pentesting#cloud-workload-protection+4 |
| 2022-08-10 | Tool demo | Blackhat |
AzureGoat : A Damn Vulnerable Azure Infrastructure
| Jeswin Mathai, Nishant Sharma, Rachna Umaraniya | #azure#cloud-pentesting#cloud-workload-protection+3 |
| 2022-08-10 | Tool demo | Blackhat |
HazProne : Cloud Hacking
| Devansh Patel, Staford Titus S | #cloud-pentesting#cloud-workload-protection#aws+4 |
| 2022-08-10 | Tool demo | Blackhat |
Vajra - Your Weapon To Cloud
| Raunak Parmar | #cloud-pentesting#cloud-security-posture-management#azure+3 |
| 2022-07-23 | Talk | Hope |
Combating Ransom-War: Evolving Landscape of Ransomware Infections in Cloud Databases
| Aditya K Sood | #ransomware#cloud-pentesting#data-protection |
| 2022-06-01 | Talk | Securityfest |
Exploitation and automated detection of threats to modern cloud infrastructure
| Krishnaa Srinivasa, Maithri Nadig | #aws#vulnerability-assessment#cloud-monitoring+4 |
| 2022-05-12 | Tool demo | Blackhat |
ThunderCloud: Attack Cloud Without Keys!
| Shivankar Madaan | #aws#cloud-pentesting#phishing |
| 2021-11-18 | Talk | Hackinparis |
Is it really an intrusion if you get called in?: Mis-configuration based attacks in AWS
| Kavisha Sheth | #aws#cloud-workload-protection#cloud-pentesting+3 |
| 2021-11-11 | Tool demo | Blackhat |
DejaVu ++
| Bhadreshkumar Patel, Harish Ramadoss | #blueteam#cloud-access-security-broker#cloud-compliance+4 |
| 2021-11-10 | Tool demo | Blackhat |
Kubestriker: A Blazing Fast Security Auditing Tool
| Vasant Kumar | #kubernetes#cloud-workload-protection#container-security+3 |
| 2021-08-04 | Tool demo | Blackhat |
Kubestriker: A Blazing Fast Kubernetes Security Auditing Tool
| Pralhad Chaskar, Vasant Kumar | #kubernetes#cloud-workload-protection#container-security+4 |
| 2020-03-06 | Talk | Nullcon |
Cloud As an Attack vector
| Ashwin Vamshi, Rushikesh Vishwakarma | #cloud-pentesting#exploitation#aws |
| 2019-11-28 | Talk | Deepsec |
Mastering AWS Pentesting and Methodology
| Ankit Giri | #aws#security-assessment#cloud-pentesting+1 |
| 2019-09-27 | Talk | C0c0n |
Building a cloud security monitoring and auditing framework
| Nirali Shah, Prasoon Dwivedi | #blueteam#cloud-monitoring#cloud-pentesting+4 |
| 2019-09-27 | Talk | C0c0n |
Doing SecOps for the Cloud using Cloud Native Services
| Akash Mahajan | #blueteam#cloud-workload-protection#container-security+3 |
| 2019-08-08 | Talk | Defcon |
Anatomy of cloud hacking
| Pratik Shah | #cloud-pentesting#post-exploitation#architecture+1 |
| 2019-05-21 | Talk | Phdays |
GDALR: an efficient model duplication attack on black-box machine learning models
| Rewanth Tammana, Nikhil Joshi | #red-teaming#machine-learning#api-security+3 |
| 2019-05-09 | Talk | Hitbsecconf |
GDALR: Duplicating Black Box Machine Learning Models
| Rewanth Tammana, Nikhil Joshi | #machine-learning#red-teaming#api-security+2 |
| 2018-10-05 | Talk | C0c0n |
Unconventional vulnerabilities in Google Cloud Platform
| Pranav Venkat | #gcp#red-teaming#cloud-pentesting+3 |
| 2018-03-01 | Talk | Nullcon |
Breaking Into Container Orchestrators
| Nadeem Hussain | #red-teaming#cloud-workload-protection#container-security+2 |
| 2017-08-18 | Talk | C0c0n |
Cloud_Security Suite - One stop tool for auditing cloud infrastructure
| Shivankar Madaan, Jayesh Chauhan | #aws#blueteam#cloud-monitoring+4 |
| 2015-08-01 | Talk | C0c0n |
S3curi7y at 36K feet
| Rugved Mehta, Gaurav Trivedi | #aws#azure#gcp+3 |
| 2013-11-07 | Talk | Groundzerosummit |
Abusing Google Apps: Google is my command and control center
| Ajin Abraham | #android#red-teaming#cloud-pentesting+4 |
| 2013-08-16 | Talk | Usenix |
Building Securable Infrastructure: Open-Source Private Clouds
| Pravir Chandra | #cloud-pentesting#architecture#open-source-security |
| 2011-10-08 | Talk | C0c0n |
Stratagemizing Security Against Perpetrators In Cloud Infrastructure
| K S Abhiraj | #blueteam#cloud-security-posture-management#cloud-pentesting+4 |
| 2009-11-18 | Talk | Securitybyte |
Cloud Hacking β Distributed Attack & Exploit Platform
| Shreeraj Shah | #red-teaming#cloud-pentesting#cloud-workload-protection+1 |