
cloudformation-waf-acl
An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to…

This tool is used to find php info page

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

Mogwai Java Management Extensions (JMX) Exploitation Toolkit

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Hands-on lab demonstrating Kubernetes container hardening by comparing default vs. security-enhanced deployments of a vulnerable note-taking…

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]



JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple…


Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…