
CRT
Audits Azure AD and Exchange Online configurations for hard-to-find permissions, federation trusts, mail forwarding rules, and delegated access to…

Audits Azure AD and Exchange Online configurations for hard-to-find permissions, federation trusts, mail forwarding rules, and delegated access to…

A Public Package Scanner for The Community

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Infrastructure Automation

The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides…

Azure Red Team tool for graphing Azure and Azure Active Directory objects

Proof of concept demonstrating Server-Side Request Forgery in ChatGPT, allowing attackers to force the AI to make arbitrary HTTP requests, exposing…

Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Curated timeline of AWS S3 bucket misconfigurations, exposed data, and leaked IAM credentials, with incident links for cloud security defenders and…

Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

Pentester-focused Docker registry tool to enumerate and pull images

Proof of Concept exploit for Kubernetes CVE-2020-8559