
LabS4U2Self
Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

Brute Force Wordpress Blogs.

WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Open Source Identity and Access Management For Modern Applications and Services

Free universal database tool and SQL client

A tool for secrets management, encryption as a service, and privileged access management

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Infisical is the open-source platform for secrets, certificates, and privileged access management.

The easiest, and most secure way to access and protect all of your infrastructure.

The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.

Provides open-source SSO and identity provider functionality with SAML, OAuth2/OIDC, LDAP, and RADIUS support for centralized authentication,…

FreeRDP is a free remote desktop protocol library and clients

Authorization library enforcing ACL, RBAC, ABAC, and custom access-control models with RESTful matching and policy management APIs for applications…

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the…

A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers.