
teleport
The easiest, and most secure way to access and protect all of your infrastructure.

The easiest, and most secure way to access and protect all of your infrastructure.

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

Automated testing to find logic and performance bugs in database systems

Open-source vulnerability database aggregating CVE data from multiple sources with a web UI and API. Maps vulnerabilities to specific software…

Pull Request-like Review/Approval flow for database queries. For compliant but smooth Engineering access to production.

A collection of web pages vulnerable to SQL injection flaws

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

Extract a slice of your production database to reproduce bugs locally. Point dbslice at a record, it follows foreign keys and gives you a complete,…

Tool designed to help identify open Elasticsearch servers that are exposing sensitive information

An modular asset discovery framework written in python to automate the repeating manual work

OSINT tool to search, parse and dump only the open Elasticsearch and MongoDB directories that have the data you care about exposing

A python library to automate time-based blind SQL injection

Allow exporting the information downloaded with sqlmap to a relational Database like Postgres and sqlite

MAD-CAT (Meow Attack Data Corruption Automation Tool) is a comprehensive security tool designed to simulate data corruption attacks against multiple…

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Strafer: A tool to detect potential infections in Elasticsearch instances

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…