
CVE-2024-3094-patcher
Ansible playbook that detects vulnerable xz-utils versions (5.6.0, 5.6.1) and installs a safe version to mitigate CVE-2024-3094 backdoor.

Ansible playbook that detects vulnerable xz-utils versions (5.6.0, 5.6.1) and installs a safe version to mitigate CVE-2024-3094 backdoor.

OPA Gatekeeper constraint policy that detects and prevents Kubernetes clusters from being vulnerable to CVE-2020-8554, enforcing secure configuration.

PowerShell script to apply Windows registry mitigation for CVE-2018-3639 (Speculative Store Bypass), enabling automated security hardening against…

Ansible playbook to update APT packages, addressing CVE-2019-3462 by automating patch deployment for vulnerability remediation.

Security risk analysis for Kubernetes resources

Multi-cloud security compliance scanner using Cloud Custodian and Nuclei engines to audit resources against CIS benchmarks and vulnerability rules…

Audits Kubernetes clusters for common security misconfigurations, including privileged containers, root filesystems, and missing AppArmor. Supports…

Puppet Module to help fix and migrate a Puppet deployment (CVE-2011-3872)

Deploy a FullStack Prodo-Typing Agent into your AWS Account (OpenClaw, Kiro-Cli, Pi, Hermes, Claude Code, Codex)

Microsoft Sentinel SIEM Log Source Analyzer

Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).

Open Cloud Security Posture Management Engine

Automatically harden systemd services by generating optimal sandboxing options from strace profiling, raising security level without breaking…

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

Suppress vulnerabilities applying Kubernetes context to scans

Infrastructure cloud modulaire, redondante et 100% souveraine pour s'affranchir des GAFAM. Guides techniques, architecture Zero-Trust et chiffrement…

Ansible playbook to automate mitigation of CVE-2023-46747 (BIG-IP unauthenticated RCE) by applying F5's official script across multiple devices.