
shh
Systemd Hardening Helper - Mirror of https://github.com/desbma/shh

Systemd Hardening Helper - Mirror of https://github.com/desbma/shh

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

Finds internet-exposed resources in an AWS account

Arbitary Code Execution in Unsecured Apache Spark Cluster

CVE-2026-42897 - Exchange Health Checker blind spot: outbound IIS URL Rewrite rules silently ignored, making EOMT mitigations invisible in diagnostic…

One command grades your whole cloud account — misconfigurations, missing observability, and security posture.

Apache Hadoop YARN ResourceManager - Unauthenticated RCE PoC

Ansible playbook to automate mitigation of CVE-2023-46747 (BIG-IP unauthenticated RCE) by applying F5's official script across multiple devices.

A terminal-based AWS Security Scanner with 102+ security checks across VPC, IAM, S3, CloudTrail, containers (ECS/EKS), and AI attack detection.…

CVE-2021-33104 - Improper access control in the Intel(R) OFU software

Script - Workaround instructions to address CVE-2021-44228 in vCenter Server

DaemonSet с реализацией временной меры для митигации уязвимости Copy Fail (CVE-2026-31431)

CVE-2025-14269 PoC exploit

Aws S3 Tko Tool

Program ini adalah alat (tool) yang dibuat untuk memeriksa keamanan sistem Minio terkait dengan kerentanan CVE-2022-35919

IngressNightmare (CVE-2025-1974)

RiskScanner 是开源的多云安全合规扫描平台,基于 Cloud Custodian 和 Nuclei 引擎,实现对主流公(私)有云资源的安全合规扫描和漏洞扫描。