
spire
Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

An open source, self-hosted implementation of the Tailscale control server

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073

Boundary enables identity-based access management for dynamic infrastructure.

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Exploit PoC and vulnerable admission webhook for CVE-2026-5556, demonstrating Kubernetes admission controller bypass via case-sensitive pod name…

PlaceOS authentication service and API gatekeeper.

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC

A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.

A lightweight, policy-driven framework that brings Zero-Trust micro-segmentation to SOHO networks using WireGuard.

Zero-Trust SSH CA

DSC resources to simplify administration of certificates on a Windows Server.