
SCOPE
AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

Clean accounts over permissions in GCP infra at scale

Salesforce object access auditor

Firecracker made simple. Spin up secure microVMs in milliseconds, from install to interactive shell in one command.

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

This repository holds a target infrastructure you can use for running the nimbostratus tools.

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

S3 Account Search

Plugin for integrating Trivy with Aqua Security platform to scan IaC, pipelines, and dependencies for vulnerabilities and misconfigurations.

Suppress vulnerabilities applying Kubernetes context to scans

Microsoft Sentinel SIEM Log Source Analyzer

WorldFirst (Public) Docker API Exploit - My security researches involving Docker and Openshift

Zero-Trust SSH CA

Script to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228

Patch openssl #heartbleed with ansible

Detection script for CVE-2026-31431 (Copy Fail) that checks kernel version, patch presence, kernel configs, AF_ALG socket availability, setuid…

AWS Testing and Reporting Management Tool