
heroku-CVE-2013-0269
Inspect all of your Heroku apps for vulnerable versions of the JSON gem

Inspect all of your Heroku apps for vulnerable versions of the JSON gem

Proof of concept exploit for CVE-2025-9074 - Unauthenticated Docker Engine API container escape affecting Docker Desktop < 4.44.3 on Windows and…


Tester for CVE-2026-43284

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

Providing Azure pipelines to create an infrastructure and run Atomic tests.

Proof-of-concept for CVE-2021-31166 (http.sys RCE) with Terraform deployment on AWS, including testing scripts and a WAFv2 rule to block the exploit.

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

a Damn Vulnerable Serverless Application

CLI tool for the Horizon3.ai API

Hands-on lab demonstrating Kubernetes container hardening by comparing default vs. security-enhanced deployments of a vulnerable note-taking…

InSpec profile to verify a node is patched and compliant for CVE-2017-8543

Ansible playbook that applies a global JVM environment variable to mitigate the Log4j CVE-2021-44228 remote code execution vulnerability across all…

Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898