
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

A collection of awesome security hardening guides, tools and other resources

Azure AD Password Checker

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…


Entra ID Password Protection Banned Password Lists

AWS AMAZON S3 Bucket Takeover Scanner & Claim Tool

Walkthrough: ingress-nginx Configuration Injection via rewrite-target Annotation

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具

a Damn Vulnerable Serverless Application

OWASP IoT Security Verification Standard (ISVS)

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

An open source threat modeling tool from OWASP

OWASP Serverless Top 10

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

Google App Engine Flask C2 redirector

flask heroku C2 redirector template