
wardgate
Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

Apache APISIX batch-requests RCE(CVE-2022-24112)

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

Exploit tool for CVE-2026-1529, demonstrating unauthorized organization registration in Keycloak via JWT token manipulation. Includes token…

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Intel Pin-based tracer for API calls, syscalls, and instructions with anti-debug evasion, used for malware analysis and reverse engineering of packed…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

A command-line tool to check if passwords have been exposed in data breaches using the Have I Been Pwned (HIBP) API.

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…