
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

safe execution paths for agents - zero trust, zero setup, zero latency.

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Defense Against the Shai-Hulud Supply Chain Attack

Writing and sharing one YARA rule daily for 100 days


Anteater - CI/CD Gate Check Framework

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Security Scanner for Agent Skills

Anticipator is an open-source threat detection platform for multi-agent AI systems.

Static Decryptor for IcedID Malware

Config Extractor for Asyncrat/Dcrat/VenomRat

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

YARA Rule Strings Statistics Calculator and Malware Research Helper

Just a git repo for the sleepmask detection rule i found in https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike/sleep-…