Multi-Cloud Dangling DNS
Vault bind (AWS/GCP/Azure/Cloudflare) → findmytakeover → findings report. Fail-closed without cloud config.
loading
Black Hat USA Arsenal, runnable in Trickest — dangling DNS, CI/CD and browser extension surface, PQ crypto, Bedrock IAM, MCP trust boundaries, web AI agents, coding-agent policy, and HTTP/3 race evidence you can point at your own targets.
Vault bind (AWS/GCP/Azure/Cloudflare) → findmytakeover → findings report. Fail-closed without cloud config.
Seed demo Actions YAML → Trajan + coding-agent CI scan → correlate findings. Swap in your .github/workflows (offline, no token).
Domain → subfinder → httpx → AC Scanner TLS/PQC → CBOM-style evidence report. Demo default cloudflare.com; or feed a host list.
Org/account Bedrock phantom scan + offline ABSK decode + SCP/detection pack + dry-run cleanup → correlate. Smoke fail-closed without AWS.
Seed demo MV3 zip → ThreatXtension static scan → correlate findings. BYO .zip/.crx or Chrome Web Store id.
HoneyMCP ghost-tool catalog + MCParasite channel inventory → correlate. Smoke needs no SaaS tokens.
Seed page URLs → httpx → WebAgentAudit probes for injection, prompt leak, jailbreak, role confusion → correlate.
Seed demo agent-action events → AgentsLeak evaluate + GolemHalt Cedar/YARA inventory → correlate allow/alert/block. BYO hook captures.
QuicDraw baseline GET vs concurrent race → diff → correlate. Demo cloudflare-quic.com; BYO same HTTPS/h3 URL on Input and Scan nodes.
Each card opens the real Library workflow page for that unit, with Collection chrome on the graph. These are the Tier A graphs from Black Hat Edition — same DAGs as in the public Library space.