
CYBERDUDEBIVASH-5G-Core-Key-Rotation-Ghost-Admin-Auditor
Production-grade tool for detecting & remediating CVE-2026-0622 (Ghost Admin privilege escalation & master key exposure in 5G core software).

Production-grade tool for detecting & remediating CVE-2026-0622 (Ghost Admin privilege escalation & master key exposure in 5G core software).

Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

A collection of awesome security hardening guides, tools and other resources

Azure AD Password Checker

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

Entra ID Password Protection Banned Password Lists

AWS AMAZON S3 Bucket Takeover Scanner & Claim Tool

Walkthrough: ingress-nginx Configuration Injection via rewrite-target Annotation

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具

a Damn Vulnerable Serverless Application

OWASP IoT Security Verification Standard (ISVS)

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

An open source threat modeling tool from OWASP

OWASP Serverless Top 10

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…