
s3crets_scanner
Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

Runtime governance for AI agents. Allow, warn, or block every model and tool call before it commits. Hash-chained audit for every decision.…

Directory/File, DNS and VHost busting tool written in Go

A command line security audit tool for Amazon Web Services

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

Free universal database tool and SQL client

A tool for secrets management, encryption as a service, and privileged access management

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

ProjectDiscovery's Open Source Tool Manager

A tool to scan Kubernetes cluster for risky permissions

Automated Bitwarden vault backup tool with AES-256 encryption, Argon2 key derivation, multi-cloud upload support, and real-time notifications via…

cMCP: Confidential MCP Gateway. Hardware-attested policy enforcement for MCP tool calls.

A terminal based tool for managing secrets with both tui and cli support

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)