
oauthseeker
A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Scans AWS IAM configurations for shadow admins by detecting misconfigured deny policies that fail to restrict user actions on groups, enabling…

MDE/MDI Defender setup for Ludus

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

Powerful protection for AI agents - Open-source security and cost tracking for AI applications

Flask library for building SAML Service Providers and Identity Providers

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

Tokend module for OS X with support for all cards supported by OpenSC

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…


credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…