
opa
Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

HardeningKitty - Checks and hardens your Windows configuration

Automation to assess the state of your M365 tenant against CISA's baselines

Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening…

Subdomain takeover vulnerability checker

An ADCS honeypot to catch attackers in your internal network.

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

Scans Infrastructure as Code files for security misconfigurations and vulnerabilities using KICS, with Bitbucket Code Insights reporting.

Scans Git repositories for hardcoded secrets, keys, and passwords using Gitleaks, integrating security into Bitbucket Pipelines with Code Insights…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

Exploit for CVE-2021-44667 targeting Alibaba Nacos 2.0.3, enabling unauthenticated remote code execution via a crafted request to the Derby database…

CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Discover Log4Shell vulnerability [CVE-2021-44832]

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…