
log4jhound
Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…
Automated deployment of OWASP Juice Shop on Kubernetes using kubeadm and Terraform, with integrated Trivy vulnerability scanning for DevSecOps…

A service that analyzes docker images and scans for vulnerabilities

Scan codebases and GCP projects for exposed API credentials

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

sprint encode (plan text) get enc password

Vulnerable app with examples showing how to not use secrets

Static code analysis tool based on Elasticsearch

AI runtime inventory: discover shadow AI, trace LLM calls

Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…