
nginx-rift-check
Detects the CVE-2026-42945 rewrite pattern in nginx configs: rewrite with ? in the replacement plus an unnamed capture consumed in the same location

Detects the CVE-2026-42945 rewrite pattern in nginx configs: rewrite with ? in the replacement plus an unnamed capture consumed in the same location

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

InSpec-based compliance profile for auditing Linux system hardening against security baselines, ensuring consistent configuration across…

Run any command inside a restricted filesystem view on Linux

A Git-native dependency admission controller. Evaluates trust signals on every dependency change and blocks commits or builds when packages fail your…


PowerShell remediation for CVE-2013-3900 (WinVerifyTrust) / Tenable Plugin 166555 using EnableCertPaddingCheck.

DevSec SSH Baseline - InSpec Profile

DevSec MySQL Baseline - InSpec Profile

Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with…

Anteater - CI/CD Gate Check Framework

DevSec Nginx Baseline - InSpec Profile

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

Hayat is a script for report and analyze Google Cloud Platform resources.

dawg the hallway monitor - monitor operating system changes and analyze introduced attack surface when installing software