
DevAudit
Open-source, cross-platform, multi-purpose security auditing tool

Open-source, cross-platform, multi-purpose security auditing tool

Open source compliance tool for development platforms.

AzureGoat : A Damn Vulnerable Azure Infrastructure

SSH agent that creates and manages TPM-sealed keys for hardware-bound authentication, supporting key generation, import, wrapping, PIN protection,…

GCPGoat : A Damn Vulnerable GCP Infrastructure

Kubernetes operator for injecting chaos experiments into cloud-native workloads, automating resilience testing and workload hardening through…

S3 Account Search

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

Mitigates CVE-2016-5195 aka DirtyCOW

A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").

DEPRECATED: Chef cookbook to audit & remediate "Shellshock" (BASH-CVE-2014-7169)

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Kubernetes-native security operator that automates vulnerability scanning, configuration auditing, secret detection, RBAC analysis, and compliance…

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Step-by-step tutorial for detecting CVE-2024-3094 (XZ Backdoor) in container images using Trend Micro Vision One TMAS CLI, with automated scanning…

Working exploit for CVE-2024-21626, a runC/Docker container escape via working directory symlink attack, enabling host filesystem access.

EU focused compliance MCP server

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.