github-actions-goat
github-actions-goat copied to clipboard
Improve dns exfiltration tutorial
trafficstars
- [ ] simulate exfiltration of token instead of repo (idea)
- [ ] add block mode in harden-runner
- [ ] add missing domain - storage.googleapis.com
@varunsh-coder I retried running the workflow https://app.stepsecurity.io/github/arjundashrath/supply-chain-goat/actions/runs/1846742924 and there is not any call to storage.googleapis.com