
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

Automated System Hardening Framework

Container escape on any docker container with healthcheck enabled via CVE-2026-31431

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

Scan codebases and GCP projects for exposed API credentials

Scans exported Azure domain dumps for plaintext passwords, connection strings, storage keys, and other secrets; generates redacted CSV/HTML reports…

Cryptographically verifiable web archiving. Playwright capture → SHA-256 Merkle hash → Bitcoin-anchored OpenTimestamps → permanent Arweave storage.

A service that analyzes docker images and scans for vulnerabilities

AI runtime inventory: discover shadow AI, trace LLM calls

Arbitary Code Execution in Unsecured Apache Spark Cluster

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Exploit for CVE-2021-44667 targeting Alibaba Nacos 2.0.3, enabling unauthenticated remote code execution via a crafted request to the Derby database…

Azure mindmap for penetration tests