
GraphStrike
Cobalt Strike HTTPS beaconing over Microsoft Graph API

Cobalt Strike HTTPS beaconing over Microsoft Graph API

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

PowerShell tool for enumerating Azure AD users, devices, applications, and domains via Microsoft Graph API, with offline data export capability.

Simple and flexible tool for managing secrets

A reverse proxy like nginx, built on pingora, simple and efficient.

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

A simple file-based scanner to look for potential AWS access and secret keys in files

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Domain-independent back end for rolling out software updates to constrained edge devices, controllers, and gateways over IP-based infrastructure,…

ProjectDiscovery's Open Source Tool Manager

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…

Curated list of awesome projects and resources related to Rust and computer security

Kubolt utility for scanning public kubernetes clusters

CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.

PHP poc, exploit for CVE-2025-9074