
CVE-2025-1974
A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

Minimal Next.js 14.0.0 demo app for CVE-2024-34351 SSRF vulnerability. Includes exploit setup, interactsh confirmation, Burp interception, and AWS…

Secure and fast microVMs for serverless computing.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Validation of best practices in your Kubernetes clusters

Hunt for security weaknesses in Kubernetes clusters

A tool for quickly evaluating IAM permissions in AWS.

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

AI-powered offensive security testing using autonomous agents, directly in your terminal.

Discover resources created in an AWS account.

Find exposed data in Azure with this public blob scanner

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️