
kubescape
Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228

Kubernetes Security Training Platform - focusing on security mitigation

CTWall (ChainThreatWall) platform helps Security, DevOps, and Product teams make risk decisions faster by using SBOM/BOM data to identify malware in…

Exploit for CVE-2023-49109 targeting Apache DolphinScheduler, a cloud-native data orchestration platform. Enables security testing of workflow…

Scans Docker Hub images using regex patterns to extract exposed secrets, private keys, and authentication tokens for security auditing and incident…

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

Linux, macOS and Windows Install scripts for cnquery & cnspec

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

Open Source Cloud Native Application Protection Platform (CNAPP)

☸️ The Open Testing Platform for AI-Driven Engineering Teams

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Run untrusted AI code safely, fast

ProjectDiscovery Cloud - Agent

Exploit for CVE-2023-51770 targeting Apache DolphinScheduler versions 3.2.1 and earlier, enabling remote code execution via crafted workflow…

Exploit for CVE-2023-51770 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in data source configuration.