
jit
Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Passive Linux host vulnerability scanner for CVE-2026-31694: checks running kernel, FUSE config, package metadata, and patch evidence, then generates…

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

Check for LDAP protections regarding the relay of NTLM authentication

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

HardeningKitty - Checks and hardens your Windows configuration

Automation to assess the state of your M365 tenant against CISA's baselines

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Defensive detection & mitigation tool for CVE-2026-31431 ("Copy Fail") — Linux kernel algif_aead LPE. No exploit code included.

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

😎 Awesome list of all things related to Microsoft Entra

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool