


Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

EU focused compliance MCP server

Offline browser-based multi-cloud posture workbench that simulates attack paths, audits IaC compliance, analyzes identity graphs, and maps audit logs…

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

simply nodes and graphs

AI runtime inventory: discover shadow AI, trace LLM calls

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)

HTTP Web Server probing

Professional Service scripts to aid in the identification of affected Java applications in TeamServer

kali-linux-docker

GitHub Actions Pipeline Enumeration and Attack Tool

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

Catch what's lurking in your Kafka clusters.

Finding exposed secrets and personal data in GitLab

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection