Skip to content
@RhinoSecurityLabs

Rhino Security Labs

A boutique penetration testing and security assessment firm in Seattle, WA.

Pinned Loading

  1. pacu pacu Public

    The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

    Python 5.3k 800

  2. cloudgoat cloudgoat Public

    CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

    Python 3.7k 771

  3. CVEs CVEs Public

    Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs

    Python 908 249

  4. IAMActionHunter IAMActionHunter Public

    An AWS IAM policy statement parser and query tool.

    Python 200 18

  5. IPRotate_Burp_Extension IPRotate_Burp_Extension Public

    Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

    Python 895 150

  6. ccat ccat Public

    Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

    Python 653 109

Repositories

Showing 10 of 15 repositories
  • pacu Public

    The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

    RhinoSecurityLabs/pacu's past year of commit activity
    Python 5,329 BSD-3-Clause 799 22 16 Updated May 19, 2026
  • cloudgoat Public

    CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

    RhinoSecurityLabs/cloudgoat's past year of commit activity
    Python 3,729 BSD-3-Clause 771 17 (1 issue needs help) 7 Updated Apr 28, 2026
  • IPRotate_Burp_Extension Public

    Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

    RhinoSecurityLabs/IPRotate_Burp_Extension's past year of commit activity
    Python 895 150 2 0 Updated Feb 23, 2026
  • IAMActionHunter Public

    An AWS IAM policy statement parser and query tool.

    RhinoSecurityLabs/IAMActionHunter's past year of commit activity
    Python 200 Apache-2.0 18 1 0 Updated Feb 10, 2026
  • GCP-IAM-Privilege-Escalation Public

    A collection of GCP IAM privilege escalation methods documented by the Rhino Security Labs team.

    RhinoSecurityLabs/GCP-IAM-Privilege-Escalation's past year of commit activity
    Python 426 BSD-3-Clause 78 6 3 Updated Oct 6, 2025
  • CVEs Public

    Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs

    RhinoSecurityLabs/CVEs's past year of commit activity
    Python 908 BSD-3-Clause 249 0 1 Updated Jun 4, 2025
  • dsnap Public

    Utility for downloading and mounting EBS snapshots using the EBS Direct API's

    RhinoSecurityLabs/dsnap's past year of commit activity
    Python 95 BSD-3-Clause 9 6 2 Updated Mar 17, 2025
  • GCPBucketBrute Public

    A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.

    RhinoSecurityLabs/GCPBucketBrute's past year of commit activity
    Python 574 BSD-3-Clause 91 4 3 Updated May 26, 2023
  • Swagger-EZ Public

    A tool geared towards pentesting APIs using OpenAPI definitions.

    RhinoSecurityLabs/Swagger-EZ's past year of commit activity
    JavaScript 190 BSD-3-Clause 46 1 0 Updated Oct 27, 2022
  • little-stitch Public

    Send and receive bypassing Little Snitch alerting.

    RhinoSecurityLabs/little-stitch's past year of commit activity
    Go 14 2 0 0 Updated Jan 27, 2022

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…