
Log4j-Updater
Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management…

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

Software Component Verification Standard (SCVS)

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Python reference implementation of The Update Framework (TUF)

Supply-chain Levels for Software Artifacts

Staged static taint analysis framework for GitHub Actions workflows. Detects code injection vulnerabilities using taint-tracking and an impact…

Anteater - CI/CD Gate Check Framework

Signing-key abuse and update exploitation framework

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

Python source code auditing and static analysis on a large scale

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

Multi-layer security framework for AI agent ecosystems. Provides pre-installation skill auditing, file integrity monitoring, runtime protection, and…

A software supply chain framework powered by Nix.

LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…