
Dop2Mop
OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML…

OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML…

General toolkit related to SAP's SSO mechanism : the Logon Tickets

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

SecureCivic is a citizen-built, open source identity verification platform designed for SSA adoption. It replaces private data brokers with a secure,…


A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

CVE-2025-59501 POC code

A tool for secrets management, encryption as a service, and privileged access management

A collection of Azure AD/Entra tools for offensive and defensive security purposes

Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces…

Authentication, authorization, traceability and auditability for SSH accesses.

safe execution paths for agents - zero trust, zero setup, zero latency.

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

AWS Least Privilege for Distributed, High-Velocity Deployment

Active Directory password filter featuring breached password checking and custom complexity rules

SSH agent that creates and manages TPM-sealed keys for hardware-bound authentication, supporting key generation, import, wrapping, PIN protection,…