
Log4ShellAuditor
An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

Patch for CVE-2014-6271

Provides a security patch for CVE-2026-0915, adding strict JSON schema validation, input sanitization, and rate limiting to prevent injection and DoS…

Patch CVE-2020-5267 for Rails 4 and Rails 3

PrestaShop <1.7.8.9 Fix for CVE-2023-30839 and CVE-2023-30545

Stage two containers

TLS checking component of purpleteam

Server scanning component of purpleteam

CLI component of purpleteam