
lynis
Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Authentication, authorization, traceability and auditability for SSH accesses.

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

Open-source network access control (NAC) system with captive portal, 802.1X, BYOD management, wired/wireless enforcement, and IDS/vulnerability…

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

Automated security auditing tool for Microsoft SharePoint and Frontpage web applications. Performs version detection, configuration flaw assessment,…

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

AI-powered Windows diagnostic & auto-repair tool using Google Gemini. Detect crashes, optimize performance, scan for malware, and generate PowerShell…

Automated ACME client for obtaining and renewing Let's Encrypt TLS/SSL certificates, with plugins to deploy HTTPS on Apache, Nginx, and other web…

PHP framework for building web applications and console tools with reusable components, security best practices, and a large ecosystem of bundles.

Open-source platform for secrets, certificates, and privileged access management with secret scanning, dynamic secrets, PKI, and CI/CD integrations.…

⚙️ NGINX config generator on steroids 💉

Simple and flexible tool for managing secrets

The easiest, and most secure way to access and protect all of your infrastructure.

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…
