
HoneyWire
Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…

Proof-of-concept exploit for CVE-2020-10749 demonstrating Kubernetes MitM attacks via IPv6 rogue router advertisements between pods.

Information about Kubernetes CVE-2020-8558, including proof of concept exploit.

ProjectDiscovery Cloud - Agent

BPF-LSM mitigation for CVE-2026-31431 (Copy Fail) — denies AF_ALG socket creation cluster-wide

LLM-first deception framework: "The honeypot that talks back!™"

Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228

Zero-trust sandbox for AI agents with kernel-level filesystem jail, transparent network proxy, and YAML-based policy engine to intercept and control…

Experimental Decoy Broker

Crafting raw TCP/IP packets to send to poorly configured Kubernetes servers - CVE-2020-8558 PoC

Sets up a Docker-based Palo Alto firewall test environment and provides an exploit script to test CVE-2024-3400, enabling safe vulnerability…

Prisma Cloud Compute Admission rules to mitigate Kubernetes CVE-2020-8554

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

Docker-based exploit for CVE-2018-10933, a libssh authentication bypass vulnerability, targeting SSH services on port 2222 for penetration testing.

A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without…

Docker-based lab reproducing CVE-2023-27163 SSRF in Request-Baskets, with exploitation verification, detection script, and network-isolation…