
cve-2026-31431-check
Check local Linux mitigation/exposure status for CVE-2026-31431 "Copy Fail"

Check local Linux mitigation/exposure status for CVE-2026-31431 "Copy Fail"

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)


Security event correlation engine for ELK stack

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

Security toolkit for CVE-2025-55182 (React2Shell) — scan, detect, correlate, and test React Server Components RCE vulnerability

Monitors cryptographic integrity of container images, releases, and Git tags for supply chain security, verifying Sigstore cosign signatures with…

Recursive vulnerability scanner for Log4j CVEs in archives and Docker images. Detects JndiLookup.class and vulnerable versions via SHA256 hashes,…

Shell scripts to detect CVE-2024-3094 backdoor in liblzma5 across Kubernetes pods and Docker containers, with SBOM generation via Trivy for…

DShield Sensor Log Collection with ELK

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

eBPF-based Linux security monitor and threat hunter providing chronologically ordered, container-aware events with on-host correlation for incident…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

the ps utility, with an eBPF twist and container context

LLM-first deception framework: "The honeypot that talks back!™"

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

CTWall (ChainThreatWall) platform helps Security, DevOps, and Product teams make risk decisions faster by using SBOM/BOM data to identify malware in…