
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

Developer-first CLI for scanning open-source dependencies, application code, container images, and IaC configurations for vulnerabilities and…

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Automating situational awareness for cloud penetration tests.

Vulnerable-by-design AWS deployment tool for hands-on cloud security training. Deploys curated CTF scenarios to practice IAM enumeration, privilege…

Serverless AWS pipeline that scans uploaded files with YARA rules in real-time, triggering alerts for malware detection and enabling rapid incident…

Serverless task distribution framework that parallelizes CLI tools across thousands of cloud functions for rapid reconnaissance and data processing.

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

Proof-of-concept exploit for CVE-2026-9999, demonstrating path traversal in serverless object storage events that overwrites function source code to…

PoC for CVE-2026-22015: malicious event injects environment variables into serverless functions, overwriting secrets and enabling privilege…

PoC exploit for CVE-2026-21002 serverless cold-start credential leakage, demonstrating how reused Lambda /tmp directories expose AWS secrets to other…

Cursor plugin teaching Hono v4 best practices with 59 LLM anti-patterns, security defaults, and Cloudflare Workers gotchas. Includes rules, skills,…

Exploit for CVE-2025-69256, a pre-auth command injection in Serverless Framework MCP server, enabling RCE via workspaceRoots injection with…

Secure and fast microVMs for serverless computing.