
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

AI runtime inventory: discover shadow AI, trace LLM calls

Scans exported Azure domain dumps for plaintext passwords, connection strings, storage keys, and other secrets; generates redacted CSV/HTML reports…

Container escape on any docker container with healthcheck enabled via CVE-2026-31431

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Scan codebases and GCP projects for exposed API credentials

Cryptographically verifiable web archiving. Playwright capture → SHA-256 Merkle hash → Bitcoin-anchored OpenTimestamps → permanent Arweave storage.

Exploit for CVE-2021-44667 targeting Alibaba Nacos 2.0.3, enabling unauthenticated remote code execution via a crafted request to the Derby database…

Automated System Hardening Framework

Azure mindmap for penetration tests

A service that analyzes docker images and scans for vulnerabilities

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

Arbitary Code Execution in Unsecured Apache Spark Cluster