
log4jhound
Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

sprint encode (plan text) get enc password

Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Scan codebases and GCP projects for exposed API credentials

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

AI runtime inventory: discover shadow AI, trace LLM calls

Static code analysis tool based on Elasticsearch

Vulnerable app with examples showing how to not use secrets

Automated deployment of OWASP Juice Shop on Kubernetes using kubeadm and Terraform, with integrated Trivy vulnerability scanning for DevSecOps…

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

A service that analyzes docker images and scans for vulnerabilities