
AIOstack
AI runtime inventory: discover shadow AI, trace LLM calls
Tools for managing user identities, authentication, authorization, and access controls within systems and networks.

AI runtime inventory: discover shadow AI, trace LLM calls

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

An AWS IAM policy statement parser and query tool.

CVE-2025-29927 Proof of Concept

Scans AWS IAM configurations for shadow admins by detecting misconfigured deny policies that fail to restrict user actions on groups, enabling…

In-memory token vault BOF for Cobalt Strike

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Low-memory graphdb with Bolt+tls support, at-rest encryption & vectors designed for local replica graph use cases.

shiro-cve-2020-17523 漏洞的两种绕过姿势分析 以及配套的漏洞环境

MDE/MDI Defender setup for Ludus

Veeam Backup Enterprise Manager Authentication Bypass (CVE-2024-29849)

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…