
secureCodeBox
Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Deploy a FullStack Prodo-Typing Agent into your AWS Account (OpenClaw, Kiro-Cli, Pi, Hermes, Claude Code, Codex)

Cryptographically signed, replay-verifiable evidence layer for AI agents. Governs actions in the loop, produces Ed25519-signed receipts linked into a…

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

Like Envoy xDS, but for eBPF filters

Millisecond microVM sandbox forking for AI agents on Kubernetes. Firecracker VMs that restore from memory snapshots in milliseconds, fork a running…

Experimental Decoy Broker

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

Superseded by https://github.com/aquasecurity/trivy-operator


Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

Cloud-native system telemetry pipeline that collects, processes, and exports system call events into a compact object-relational format for…

Post-exploit a compromised etcd, gain persistence and remote shell to nodes.

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…