
aws-doctor
Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Automation to assess the state of your M365 tenant against CISA's baselines

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…



Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption


Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data


Scan for misconfigured S3 buckets across S3-compatible APIs!