
easywall
Web interface for the nftables firewall on Linux, written in Go. The apply undoes itself after 120 seconds unless you confirm it — you cannot lock…

Web interface for the nftables firewall on Linux, written in Go. The apply undoes itself after 120 seconds unless you confirm it — you cannot lock…

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

In-depth ldap enumeration utility

Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

Hardened Debian GNU/Linux distro auditing

Shell scanner for CVE-2026-31431 "Copy Fail" — a local privilege escalation via Linux kernel page cache corruption (algif_aead/AF_ALG). Checks kernel…

Automated scanner and patch helper for CVE-2026-31431, detecting vulnerable Linux hosts via SSH, verifying kernel versions, and applying kernel…

Check local Linux mitigation/exposure status for CVE-2026-31431 "Copy Fail"

Ansible playbook to detect and apply kernel cmdline mitigation for CVE-2026-31431 (Copy Fail) across Debian/Ubuntu/RHEL fleets, with read-only…

Automated Tor-based shared web hosting server with PHP multi-version support, email routing, auto-scaling Tor instances, and built-in security…

USB port access control tool for Debian with whitelist management, automatic background scanning daemon, and CLI interface to block or allow USB…

dawg the hallway monitor - monitor operating system changes and analyze introduced attack surface when installing software