
Metasploit-Module-TFM
Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

Notes about attacking Jenkins servers


veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

A tool to scan Kubernetes cluster for risky permissions

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

a guard that blocks catastrophic agent actions


Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Model Context Protocol server for autonomous vulnerability discovery

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple…

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure