
permission-manager
Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

SSH agent that creates and manages TPM-sealed keys for hardware-bound authentication, supporting key generation, import, wrapping, PIN protection,…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

An SSH Agent that provides SSH keys stored in Bitwarden Secrets Manager

A fingerprint module, That also adds support of passkeys to linux

OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML…

SecureCivic is a citizen-built, open source identity verification platform designed for SSA adoption. It replaces private data brokers with a secure,…

A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by…

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

A JWT based API for managing users and issuing JWT tokens

Web interface to change and reset password in an LDAP directory

Open-source access management platform offering single sign-on, adaptive authentication, authorization, and federation for secure access to web,…

Installable Claude Skills providing expert-level compliance guidance for 30+ frameworks including ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF,…

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

Creating attacks paths across management and data planes

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…