
horusec
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…


automated password spraying tool

Pentester-focused Docker registry tool to enumerate and pull images

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

A PowerShell script that automates the security assessment of Microsoft 365 environments.

GCP resource scanner that evaluates access levels of compromised credentials by enumerating cloud services, projects, and IAM permissions across…

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)