{"repo":"carlospolop/PurplePanda","free":true,"listed":false,"github":"https://github.com/carlospolop/PurplePanda","clone":"git clone https://github.com/carlospolop/PurplePanda.git","description":"Identify privilege escalation paths within and across different clouds","language":"Python","stars":719,"topics":["cloud","privesc","gcp","github","kubernetes"],"license":null,"category":"deployment-docker-iac","readme_excerpt":"PurplePanda This tool fetches resources from different cloud/saas applications focusing on permissions in order to identify privilege escalation paths and dangerous permissions in the cloud/saas configurations. Note that PurplePanda searches both privileges escalation paths within a platform and across platforms . The name comes from the animal Red Panda . This panda eats peas, just like Purple Panda, which can ingest API keys/tokens found by these PEASS . The color was changed to purple because this tool is meant mainly for Purple Teams (because it can be highly useful for both Blue and Red Teams ). How to use Each folder inside /intel defines one platform that can be enumerated and contains a README.md file explaining how to use that specific module . Download Neo4jDesktop and create a database. Then export the env variables PURPLEPANDA NEO4J URL and PURPLEPANDA PWD with the URL to the neo4j database and the password. If you want shodan to be used with public IPs discovered during the enumeration export a env variable called SHODAN KEY with a valid api key of shodan . Then just install and launch the program indicating the platforms you want to enumerate comma separated like. Local install Docker PurplePanda has 2 analysis modes : - -e ( enumerate ): This is the main one , it will try to gather data and analyze it. - -a ( analyze ): This will perform a quick analysis of the provided credentials . Video tutorial Check how to use and inspect the data gathered by PurplePanda: ","default_branch":null,"files":null,"tree":[],"storefront":"/r/carlospolop","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/carlospolop/PurplePanda/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}