
CSPBypass
CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

A centralized resource for previously documented WDAC bypass techniques

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

Authentication, authorization, traceability and auditability for SSH accesses.

HardeningKitty - Checks and hardens your Windows configuration

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW


Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

A very simple way to find out which SSL ciphersuites are supported by a target.

The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides…

Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.

Superseded by https://github.com/aquasecurity/trivy-operator

Analyzes DNS delegation and DNSSEC security by probing resolvers and authoritative servers, then validating, diagnosing, and visualizing zone…

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.

Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploitability…