
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

GitHub App to set and enforce security policies

Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate…

Security Tool to Look For Interesting Files in S3 Buckets

A toolkit to attack Office365

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational…

Open-source access management platform offering single sign-on, adaptive authentication, authorization, and federation for secure access to web,…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

😎 Awesome list of all things related to Microsoft Entra

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

A utility to detect various technology for a given IP address.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides…