
MakerChecker
Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

Self-hosted SSH Certificate Authority replacing static keys with short-lived certificates, enforcing WebAuthn MFA, RBAC, and tamper-evident audit…

Exploit for Antminer Monitor 0.5.0 authentication bypass via static Flask secret key, enabling admin cookie forgery and /console access.

Free universal database tool and SQL client

A tool for secrets management, encryption as a service, and privileged access management

C# tool for enumerating and exploiting misconfigurations in Active Directory Certificate Services (AD CS), enabling certificate template abuse,…

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

Temporary macOS admin rights management tool for enterprise environments. Grants time-limited administrator privileges on-demand, enhancing security…

Web-based Kubernetes RBAC management tool for creating users, assigning namespaces and permissions, and distributing Kubeconfig files via an…

A tool to scan Kubernetes cluster for risky permissions

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Peer-to-peer code collaboration and publishing stack with a secure, decentralized protocol, CLI tool, and network daemon for sovereign code forges.

DLL injection tool that bypasses guest OS login screens on VMware by manipulating allocated RAM memory to patch authentication functions.

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

C# tool for remotely requesting X.509 certificates from ADCS via DCOM/SMB, bypassing endpoint mapper. Enables ESC1/ESC6 exploitation, certificate…

SSH multiplex backdoor tool for bypassing authentication on bastion hosts and maintaining persistent access during red team operations.

A terminal based tool for managing secrets with both tui and cli support

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams