
Thunderstorm
A collector and derivation engine. It maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a…

A collector and derivation engine. It maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a…

Production-grade Security Baseline & Hardening Guide for Ubuntu 24.04/26.04 LTS. Kernel isolation, Emergency Panic Button, custom AppArmor/Firejail…

Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

Authorization engine for context-aware access control with YAML policies, RBAC/ABAC support, check/plan APIs, and GitOps-friendly deployment.

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Vault app for DC34 badge

Automation to assess the state of your M365 tenant against CISA's baselines

Tokend module for OS X with support for all cards supported by OpenSC

WebUI for AAA

Open source smart card tools and middleware. PKCS#11/MiniDriver

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

The easiest, and most secure way to access and protect all of your infrastructure.

Infisical is the open-source platform for secrets, certificates, and privileged access management.

A free, secure and open source app for Android to manage your 2-step verification tokens.

Microsoft Entra Conditional Access Documentation with PowerShell

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

Protect your domain controllers against Zerologon (CVE-2020-1472).

Isolate your big brother apps https://secure-system.gitlab.io/Insular/