
BrowserBox
💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

DejaVU - Open Source Deception Framework

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Event-driven AWS security misconfiguration detection framework that monitors multiple accounts in real-time, triggering alerts via Lambda for IAM,…

This is an incident response playbook we created for the Vercel April 2026 compromise

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

Proof-of-concept demonstrating an authorization bypass in Traefik's Kubernetes Gateway provider (CVE-2026-54761) via a crossProviderNamespaces…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…


