
gatekeeper-cve-2020-8554
OPA Gatekeeper constraint policy that detects and prevents Kubernetes clusters from being vulnerable to CVE-2020-8554, enforcing secure configuration.

OPA Gatekeeper constraint policy that detects and prevents Kubernetes clusters from being vulnerable to CVE-2020-8554, enforcing secure configuration.

Remediation task for CVE-2018-15686, CVE-2018-16866, and CVE-2018-16888 affecting SystemD in EL7

One security-remediation.sh for CVE-2026-41940 (cPanel), CVE-2026-31431 (kernel "Copy Fail"), CSF, optional domain/proxy cleanup, and optional…

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

Branchable computing by using a portable, lightweight, self-contained virtual machine

Infrastructure as code for DNS!

Validation of best practices in your Kubernetes clusters

PacBot (Policy as Code Bot)

Cloud native secrets management for developers - never leave your command line for secrets.

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

Like Envoy xDS, but for eBPF filters

Create a VPS on Google Cloud Platform or Digital Ocean easily with Offensive Docker included to launch assessment to the targets.

Clean accounts over permissions in GCP infra at scale

Ansible role to configure redirectors for red team C2

Workaround for CVE-2025-52881: Fixes Docker/Podman breakage in Proxmox LXC containers caused by AppArmor incompatibility with runc 1.2.7+. Universal…

JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package

eBPF + nftables + DNS proxy egress enforcement for GitLab Runner CI/CD job containers — community edition data plane https://leitwacht.eu/