
prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Automating situational awareness for cloud penetration tests.

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

Catch what's lurking in your Kafka clusters.

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

Python reconnaissance tool for discovering Azure services and attributing tenant ownership via DNS validation, multi-service probing, and response…

OSINT tool to evaluate the trustworthiness of a company

PoC for CVE-2021-43557

Script to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228

Proof-of-concept exploit for CVE-2024-47066, a server-side request forgery (SSRF) vulnerability in LobeChat that bypasses IP-based restrictions via…