Red Teamer with a focus on offensive Cloud and DevOps Security
- Munich, Germany
- in/benedikt-haussner
Pinned Loading
-
release-tampering-pocs
release-tampering-pocs PublicProof of Concepts for malicious maintainers: How to Tamper with Releases built with GitHub Actions Worfklows, presented at fwd:cloudsec Europe 2025
-
terraform-provider-statefile-rce
terraform-provider-statefile-rce PublicThis terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.
-
azure-storage-reverse-shell
azure-storage-reverse-shell PublicThis GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs
-
secret-env-exfiltrator
secret-env-exfiltrator PublicA GitHub Action that exfiltrates secrets and environment variables
Something went wrong, please refresh the page to try again.
If the problem persists, check the GitHub status page or contact support.
If the problem persists, check the GitHub status page or contact support.

