
SafeLine
Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

CLI framework for deploying and managing serverless applications on AWS Lambda with YAML infrastructure, local development, and multi-language…

Modlishka. Reverse Proxy.

Tool for assessing on-premises Microsoft servers authentication such as ADFS, Skype, Exchange, and RDWeb

PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

Detailed technical write-up and proof-of-concept for CVE-2022-26923, an Active Directory Certificate Services privilege escalation vulnerability,…

The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.

Robust open-source cryptography library implementing SSL/TLS protocols, general encryption, and X.509 certificate handling for secure communications.

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

Kali365 - EvilTokens Replica

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A free, secure and open source app for Android to manage your 2-step verification tokens.

The ultimate WinRM shell for hacking/pentesting

The vulnerable application that will teach you how to hack WebSockets

More private by default Firefox ESR. Fork of ghostery.

Trying to tame the three-headed dog.

This puppet module provides numerous security-related configurations, providing all-round base protection.

The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷