
heimdal
Implementation of Kerberos, PKI, and ASN.1/DER providing authentication, authorization, and cryptographic services for secure networks.

Implementation of Kerberos, PKI, and ASN.1/DER providing authentication, authorization, and cryptographic services for secure networks.

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Core framework for identity and access management, providing authentication, authorization, and identity governance capabilities for enterprise…

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

A tool to extract the IdP cert from vCenter backups and log in as Administrator

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

Cryptographically secure messaging and social networking service.

PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest…

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Authentication service for creating and validating tamper-proof user credentials in HPC cluster environments, with a portable API and no root…

Peer-to-peer code collaboration and publishing stack with a secure, decentralized protocol, CLI tool, and network daemon for sovereign code forges.

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.

Overlay network protocol giving AI agents permanent addresses, authenticated encrypted tunnels, and a trust model over UDP. Includes NAT traversal,…

Exploit script for CVE-2024-1708 and CVE-2024-1709 in ConnectWise ScreenConnect, enabling authentication bypass and remote code execution with user…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…