
openssh-portable
Portable OpenSSH

Portable OpenSSH

Secure offline storage of credentials with encrypted vaults, password generator, TOTP, YubiKey/OnlyKey support, browser integration, and CLI.

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

The cryptography-based networking stack for building unstoppable networks with LoRa, Packet Radio, WiFi and everything in between.

The easiest, most secure way to use WireGuard and 2FA.

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…

Centralizes identity, authentication, and access control for Linux/UNIX environments using LDAP, Kerberos, PKI, DNS, and Active Directory trust.

FIPS 140-3 compliant VPN kernel module and user tool, drop-in replacement for WireGuard with AES-256-GCM, SHA2-256, and SECP256R1 cryptography for…

Enhanced SSH client with TUI — manage connections, keys, and sessions

A reverse proxy like nginx, built on pingora, simple and efficient.

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Minimal terminal-based password manager

Centralized, TPM 2.0 hardware-backed cryptographic identity enclave and multi-protocol bridge for Linux (FIDO2/CTAP2 WebAuthn Passkeys, OpenSSH…

Proof-of-concept exploit for CVE-2026-39987, a pre-authentication RCE in Marimo's /terminal/ws WebSocket endpoint that yields an interactive shell…


Proof-of-concept exploit for CVE-2026-76578 and CVE-2026-76560, chaining anonymous LDAP ADD with a 389-ds SELFDN bypass to gain FreeIPA domain admin…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Modlishka. Reverse Proxy.