
DIAL
Event-driven AWS security misconfiguration detection framework that monitors multiple accounts in real-time, triggering alerts via Lambda for IAM,…

Event-driven AWS security misconfiguration detection framework that monitors multiple accounts in real-time, triggering alerts via Lambda for IAM,…

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Scans AWS IAM configurations for shadow admins by detecting misconfigured deny policies that fail to restrict user actions on groups, enabling…

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

Salesforce object access auditor

This repository holds a target infrastructure you can use for running the nimbostratus tools.

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

Salesforce Policy Deviation Checker

Finds internet-exposed resources in an AWS account

Script to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228

Suppress vulnerabilities applying Kubernetes context to scans

Workaround for CVE-2025-52881: Fixes Docker/Podman breakage in Proxmox LXC containers caused by AppArmor incompatibility with runc 1.2.7+. Universal…

CVE-2026-42897 - Exchange Health Checker blind spot: outbound IIS URL Rewrite rules silently ignored, making EOMT mitigations invisible in diagnostic…

Arbitary Code Execution in Unsecured Apache Spark Cluster


eBPF + nftables + DNS proxy egress enforcement for GitLab Runner CI/CD job containers — community edition data plane https://leitwacht.eu/

One command grades your whole cloud account — misconfigurations, missing observability, and security posture.