
puncia
Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML…

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

Curated collection of resources and analysis documenting the CVE-2024-3094 supply-chain backdoor in XZ Utils, including security advisories,…

Linux应急处置/信息搜集/漏洞检测工具,支持基础配置/网络流量/任务计划/环境变量/用户信息/Services/bash/恶意文件/内核Rootkit/SSH/Webshell/挖矿文件/挖矿进程/供应链/服务器风险等13类70+项检查

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

Collection's of Tech Talk that are presented by me :)

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

AI runtime inventory: discover shadow AI, trace LLM calls

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Sigma detection rules for AI agent security monitoring

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity