
CureIAM
Clean accounts over permissions in GCP infra at scale

Clean accounts over permissions in GCP infra at scale

CVE-2016-4468

Open security research on AI coding agent infrastructure. Agent-executable remediation manifests for CVE-2026-22812 and CVE-2026-22813.

An easy to use and powerful chaos engineering experiment toolkit.(阿里巴巴开源的一款简单易用、功能强大的混沌实验注入工具)

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Audits Azure AD and Exchange Online configurations for hard-to-find permissions, federation trusts, mail forwarding rules, and delegated access to…

Create a VPS on Google Cloud Platform or Digital Ocean easily with Offensive Docker included to launch assessment to the targets.

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).

A security toolkit for Amazon S3

Getting a handle on container security

Scan publicly accessible assets on your AWS cloud environment

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

Deploy a phishing infrastructure on the fly.

Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.

Proof-of-concept exploit for CVE-2020-8554, demonstrating Kubernetes service externalIP manipulation to achieve man-in-the-middle attacks on cluster…

Review Access - kubectl plugin to show an access matrix for k8s server resources

Zero-Trust SSH CA