
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

0-day malware detection for binaries, source & scripts (that doesn't suck)

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

a guard that blocks catastrophic agent actions

Open-source secret scanner in Rust

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Filesystem scanner for Log4Shell (CVE-2021-44228) and related CVEs. Detects vulnerable JAR files via hash matching and class presence. Runs…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Security Governance for Agentic AI

Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

An easy to use, light-weight, on-demand virus scanner for Linux systems. For additional help, see the <a…

A lightweight utility designed to detect and remediate systems affected by CVE-2024-3094, a critical vulnerability impacting [insert affected…

Proof-of-concept exploit for CVE-2019-17041, a buffer overflow in rsyslog's parser, demonstrating remote code execution.

Defense Against the Shai-Hulud Supply Chain Attack

Performed a Full & Fast vulnerability assessment using OpenVAS against Metasploitable2, identified the critical vsftpd Backdoor vulnerability…