
tusk-cli
Automated testing suite with live traffic record and replay

Automated testing suite with live traffic record and replay

Hash-based malware scanner for incident response. Scans files recursively using known malware hashes, supports multithreading, extension filtering,…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Ruby command-line interface to Burp Suite's REST API

A documentation and tracking project with the goal of making package management systems more secure.

An API hooking framework for intercepting and monitoring Windows applications

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

TLS checking component of purpleteam

Server scanning component of purpleteam

PoC de CVE-2026-35616: control de acceso indebido en FortiClient EMS.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.