
libfido2
Provides library functionality for FIDO2, including communication with a device over USB or NFC.

Provides library functionality for FIDO2, including communication with a device over USB or NFC.

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

Lightweight, secure control plane & real-time web dashboard in Crystal for Linux firewalld and NetworkManager host security.

The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.

A collection of awesome security hardening guides, tools and other resources

A curated list of awesome Security Hardening techniques for Windows.

Runtime security for AI agents: discover agents, map their permissions, and enforce what they can do.

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

A collection of Azure AD/Entra tools for offensive and defensive security purposes

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they…

Open-source access management platform offering single sign-on, adaptive authentication, authorization, and federation for secure access to web,…

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

Idempotent functions for IBM Security Appliance REST APIs. Currently covering ISAM and ISDS Appliances.

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

CyberArk Security Audit

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…