
secureCodeBox
Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Metarget is a framework providing automatic constructions of vulnerable infrastructures.

OWASP Autonomous Penetration Testing Standard

A collection of AWS penetration testing junk

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

A tool for quickly evaluating IAM permissions in AWS.

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

KVM/x86 guest-to-host escape exploit (CVE-2026-53359) leveraging a use-after-free in shadow MMU emulation. Includes PoC for triggering host kernel…

A tool to scan Kubernetes cluster for risky permissions

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

Open-source framework for hosting Attack/Defense CTF competitions with automated gamebot, script execution, VPN routing, and cloud-based…

A collection of manifests that will create pods with elevated privileges.

Cobalt Strike HTTPS beaconing over Microsoft Graph API

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.