
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

No-root network monitor, firewall and PCAP dumper for Android

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

Open source vulnerability DB and triage service.

Chiasmodon is an OSINT tool designed to assist in the process of gathering information about a target domain. Its primary functionality revolves…

Curated timeline of AWS S3 bucket misconfigurations, exposed data, and leaked IAM credentials, with incident links for cloud security defenders and…

Open Cloud Security Posture Management Engine

Whois for the Cloud: Recon tool for cloud provider attribution. Supports AWS, Azure, Google, Cloudflare, and Digital Ocean.

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

No longer maintained. Please refer to Google Threat Intelligence / Virus Total collections.

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

Microsoft Sentinel SIEM Log Source Analyzer

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

Daftar CVE 2025-2026 terupdate