
gvisor
Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

Exploit for CVE-2019-5736: runc container escape that overwrites host docker-runc binary with a payload, triggered via docker exec.

On-prem API gateway for AI coding agents with per-engineer cost attribution, hard budgets, egress governance (secrets/entity scanning), context-rot…

Cross-cloud S3-compatible object storage CLI to list, export, and download buckets across AWS, Aliyun, Tencent, Huawei and more, with anonymous…

PowerShell script to mitigate CVE-2018-12038. The script takes a list of PC as input, gets their BitLocker encryption type remotely, and outputs a…

Lab reproduction of CVE-2026-34040: bypasses Docker/Moby AuthZ plugins using oversized (>1MB) request bodies to create privileged containers with…

Docker base image with backported Host header validation fix for CVE-2025-12543 in Undertow 1.4.x, enabling secure deployment of WildFly 11…

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

A collection of scripts for assessing Microsoft Azure security

Attack Surface Management since before Attack Surface Management was a thing

SSH bastion/jump host/jumpserver

Identify IP addresses owned by public cloud providers

An AI-powered tool for discovering privilege escalation opportunities in AWS IAM configurations.

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Microsoft Sentinel SIEM Log Source Analyzer