
divd-2021-00038--log4j-scanner
Scan systems and docker images for potential log4j vulnerabilities. Able to patch (remove JndiLookup.class) from layered archives. Will detect…

Scan systems and docker images for potential log4j vulnerabilities. Able to patch (remove JndiLookup.class) from layered archives. Will detect…

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

Strafer: A tool to detect potential infections in Elasticsearch instances

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

Open source tooling to stop ICS phishing (malicious calendar invites)

Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are…

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

PoC for CVE-2021-1056, related to GPU Container Security

Suppress vulnerabilities applying Kubernetes context to scans

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

The PQC Network Scanner is a quantum‑focused network assessment tool that scans TLS/SSL certificates across enterprise environments to identify…

A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492

we are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in…