
AzureAttackKit
Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Notes about attacking Jenkins servers


Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.


Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

Model Context Protocol server for autonomous vulnerability discovery

a guard that blocks catastrophic agent actions

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…


A tool to scan Kubernetes cluster for risky permissions

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure