
CanaryHunter
Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

Audits Salesforce object-level access permissions, listing which profiles and permission sets have read/edit/delete access to all records of…

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

Service that scans your Infrastructure as Code for common vulnerabilities

Mounts AWS resources as a local filesystem for infrastructure exploration, security auditing, and configuration analysis using standard Unix tools…

Ansible playbook to patch OpenSSL against CVE-2014-0160 (Heartbleed) by upgrading packages and restarting affected services on Debian-family servers.

Comprehensive fix collection for CVE-2026-53359 KVM/x86 shadow MMU guest-to-host escape, offering livepatch, kpatch, kernel upgrade, and manual…

Terraform module to manage AWS Security Groups. Currently, the ingress and egress rules support IPv4, IPv6, and Security Group ID inputs.

Runtime security agent for GitLab Runner CI/CD that enforces network egress policies per container using eBPF, DNS proxy, and nftables to prevent…

One command grades your whole cloud account — misconfigurations, missing observability, and security posture.

Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.

Citrix NetScaler CVE Preconditions Checker as per CTX696604 | Supported CVE : CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816,…

Parallel SSH-based scanner that detects CVE-2024-41110 in Docker installations, identifies vulnerable versions and AuthZ plugins, and generates a…

Terminal-based AWS security scanner with 102+ checks across VPC, IAM, S3, CloudTrail, containers (ECS/EKS), and AI attack detection. Detects…

Proof-of-concept exploit for CVE-2021-33104, an improper access control vulnerability in Intel OFU software before version 14.1.28, enabling local…

PowerShell script to mitigate CVE-2018-12038. The script takes a list of PC as input, gets their BitLocker encryption type remotely, and outputs a…

End-to-end vulnerability management lifecycle on Azure Windows Server 2025. Features OS patching and network-level compensating controls (NSG) to…

Python script to detect vulnerable Ingress NGINX Controller versions (CVE-2025-1974) in Kubernetes clusters by auditing pod images and admission…