
kube-hunter
Hunt for security weaknesses in Kubernetes clusters

Hunt for security weaknesses in Kubernetes clusters

Security Tool to Look For Interesting Files in S3 Buckets

Microsoft Threat Intelligence Security Tools

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

An open source threat modeling tool from OWASP

Vulnerable app with examples showing how to not use secrets

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

SSRF (Server Side Request Forgery) testing resources

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking