
CVE-2025-62506
Verification script for CVE-2025-62506, a privilege escalation vulnerability in MinIO service accounts, testing if restricted accounts can bypass…

Verification script for CVE-2025-62506, a privilege escalation vulnerability in MinIO service accounts, testing if restricted accounts can bypass…

Cloud native secrets management for developers - never leave your command line for secrets.

Security risk analysis for Kubernetes resources

cMCP: Confidential MCP Gateway. Hardware-attested policy enforcement for MCP tool calls.

A collection of manifests that will create pods with elevated privileges.

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

Create your own vulnerable by design AWS penetration testing playground

TunnelX is a lightweight ingress tunneling tool designed to create a secure SOCKS5 proxy server for routing network traffic.


Batch exploit script for CVE-2019-16097, targeting Harbor container registry to create unauthorized admin accounts via crafted API requests.

Proof-of-concept exploit for CVE-2022-27518 targeting Citrix ADC and Citrix CPX containers, demonstrating remote code execution via crafted HTTP…

Privilege Escalation using nodes/proxy (create action allowed) and nodes/status (update/patch actions allowed)

Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scanning — applied…

Secure agents in seconds with permissions enforced at runtime.

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

Reconnaissance Real IP address for Cloudflare Bypass

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

Create On Demand Disposable OpenVPN Endpoints on AWS.