/ Arsenal — offensive & recon tooling

Tools

Varunastra

Engineered to detect and help mitigate vulnerabilities in Docker — secrets, CVEs and misconfigurations across containers and images. Presented at BlackHat USA 2025, Asia 2025 and MEA 2024.

Go Docker Secrets Scanning BlackHat Arsenal
View on GitHub ↗

Agneyastra

A Firebase misconfiguration detection toolkit that gives bug bounty hunters unparalleled precision. Co-presented at BlackHat Asia 2025 and Europe 2024.

Go Firebase Vulnerability Scanner BlackHat Arsenal
View on GitHub ↗

IAMX

A multi-cloud IAM enumeration CLI that discovers effective permissions across AWS, GCP and Azure — 400+ AWS services, 4000+ GCP permissions and 2000+ Azure operations, all via safe read-only methods.

Python Cloud Security IAM AWS · GCP · Azure
View on GitHub ↗

Cyclops

A free serverless alternative to Burp Suite Collaborator. Catch SSRF and blind XSS callbacks — set it up once and it keeps handling requests with no further configuration.

NodeJS Serverless SSRF Blind XSS
View on GitHub ↗