
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Security Governance for Agentic AI


a guard that blocks catastrophic agent actions

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

Scanners for Jar files that may be vulnerable to CVE-2021-44228

a fast check, if your server could be vulnerable to CVE-2021-44228

Automatically create YARA rules from malicious documents.

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

Code canaries to quickly triage hallucinated ('slop') vulnerability reports

Open-source secret scanner in Rust

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

Externalize Java application access to protected resources as log messages.

Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…