
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Automated vulnerability, misconfiguration, and rootkit scanner for AWS EC2 instances using Vuls, Lynis, and Chkrootkit via snapshot-based offline…

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

Automated Kubernetes cluster penetration testing tool that exploits misconfigurations in API, Kubelet, etcd, and Dashboard to achieve node takeover…

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Reproduces CVE-2026-42880, a critical ArgoCD vulnerability exposing Kubernetes Secrets via ServerSideDiff. Includes automated lab setup, trigger…

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

Automated PowerShell orchestrator for applying Secure Boot mitigations against CVE-2023-24932 (BlackLotus). Handles registry changes, reboots,…

Synthetic demo target for CVE-2024-10821 vulnerability detection and automated fix via compensating control. Demonstrates one-click PR-based…

Automated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

VisualCodeGrepper - Code security scanning tool.

Check UNIX/Linux systems for privilege escalation