security
Convert Kubernetes Cilium Network Policies to OpenGraph JSON BloodHound ingestion.
Related contents:
CT Log Scanner
Gungnir is a command-line tool written in Go that continuously monitors certificate transparency (CT) logs for newly issued SSL/TLS certificates. Its primary purpose is to aid security researchers and penetration testers in discovering new domains and subdomains as soon as they are issued certificates, allowing for timely security testing.
A tracker of publicly reported prompt-injection techniques, broken down by delivery method, encoding, and propagation behavior, with the models each was confirmed against, the reporting source, and (where known) the attack source. Fields are left blank when a report does not state them; techniques whose details are vague or unconfirmed are marked Not fully vetted. Nothing here is guessed.
Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK.
Automated purple-team validation of the Sigma detection rules built in detection-as-code-repo, using MITRE Caldera to execute a chained Active Directory credential-access attack path against an existing domain lab, and an ATT&CK Navigator heatmap to visualize coverage.
EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling targeting Microsoft Entra ID.
The project builds a automatic knowledge base around tools such as AzureHound, AADInternals, O365Enum, PingCastle, and others, with a focus on the UserAgent and API artifacts they generate.
Working together to detect maliciously or mistakenly issued certificates.
An ecosystem that makes the issuance of website certificates transparent and verifiable.
Related contents:
Drop sandbox for Linux. Linux sandboxing that doesn’t get in your way.
Isolate programs and coding agents without leaving your familiar work environment. Drop allows you to easily create sandboxed environments that isolate programs and coding agents while preserving as many aspects of your work environment as possible. Drop uses your existing distribution, so all the programs you've installed are available in the sandbox. Your username is preserved, and selected configuration files remain readable in the sandbox.
Enumerate user accounts and registered authentication methods via the Microsoft Self-Service Password Reset (SSPR) portal.
Probe Microsoft's Self-Service Password Reset (SSPR) endpoint to enumerate registeted verification methods and flag any that lack a strong second factor. Provides user enumeration and an approximation of MFA posture across Entra accounts.
Suppress vulnerabilities applying Kubernetes context to scans.
Vex8s generates VEX documents by correlating container vulnerabilities with Kubernetes settings to determine which CVEs are actually exploitable in your cluster.
Effective Linux Compliance
Pavois audits the configuration your services actually run, sshd -T, sysctl, systemctl show, not just the files on disk. It catches the Includes and drop-ins that file-based scanners miss, grades the result A:E, and remediates it as code.
LAN visibility and alerting tool for home networks and small offices. Self-hosted network visibility for discovering, organizing, and monitoring devices on your LAN.
LanGuard finds devices, tracks online and offline state, scans common ports, keeps network history, and can send Discord, Telegram, or automation webhook alerts when new devices appear.
Discover, mask, and verify sensitive data in SQL databases — an auditable scan → mask → validate workflow for safe database copies.
Review the package artifact before it ships. pre-publish package security. Review the artifact before you publish it: diffs the built npm/PyPI package against the last published version and pins risk signals to the changed lines.
Between your last code review and the public registry sit build scripts, bundler output, and CI credentials. Drydock diffs the exact artifact against the last published version and pins every supply-chain finding to a changed line. Workflow Gate enforces the decision on a configured protected job; Stage Watchtower records an advisory npm review.
A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital Forensics, Incident Response, Malware Analysis and Threat Hunting.
This is aimed at Professionals, Security Researchers, Students, CTF Players as well as DFIR & Malware Analysis Enthusiasts in the field of Cyber Security who want to practice or have an interest in the aforementioned topics.
Crible Algébrique: Distribution, Optimisation - Number Field Sieve.
CADO-NFS is a complete implementation in C/C++ of the Number Field Sieve (NFS) algorithm for factoring integers and computing discrete logarithms in finite fields. It consists in various programs corresponding to all the phases of the algorithm, and a general script that runs them, possibly in parallel over a network of computers. CADO-NFS is distributed under the Gnu Lesser General Public License (LGPL) version 2.1 (or any later version).
Related contents:
27 Security Intelligence Tools for Claude.
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
Offensive AD tradecraft in a browser tab.
A suite of Active Directory attack tools built as Chrome Isolated Web Apps. Raw TCP straight from a signed web app via the Direct Sockets API — no loader, no PE, no third-party libraries. Kerberos, TLS and DCE-RPC hand-rolled in JavaScript.
Pentest Harness — Heaven for Hackers. A self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Bring your own AI model API; sessions stay local.
An open-source, dark-first AI agent harness for authorized penetration tests, bug bounty research, security labs, and CTF engagements. Built on a plugin architecture where every layer — model adapters, tools, sessions, settings, and credentials — is replaceable from configuration.
Works with any AI model API. Bring your own key from OpenAI, Anthropic, DeepSeek, Google, Mistral, Groq, OpenRouter, Azure OpenAI, or any OpenAI-compatible gateway — one click auto-discovers your models and you're running.
AWS Bloodhound OpenGraph Connector.
awshound collects AWS IAM/authorization data and builds a BloodHound OpenGraph.
Related contents:
My useful files for penetration tests, security assessments, bug bounty and other security related stuff.
A.I.G (AI-Infra-Guard) is a comprehensive, intelligent, and user-friendly AI Red Teaming security testing platform developed by Tencent Zhuque Lab.
Detection Skills is an open standard for the Agentic SOC, that transforms static detections into agentic workflows. Designed and used by Cyber Defense Engineers, it brings the best your team can do - to every alert.
Reference architecture for AI agents that propose actions but cannot authorize them — immutable intent capture, an independent Decionis policy verdict (ALLOW/ESCALATE/BLOCK), verified human approval, and a SafeExecutor that consumes a single-use intent-bound grant.
Varnish Orca is a Virtual Registry Manager: a fast pull-through cache for artifact registries. Control which packages reach your developers, pipelines, and agents.
Deploy it close to your developers and CI/CD pipelines to reduce build times and egress costs.
Related contents:
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
Open Source Integration Layer for AI Agents. Add any integration in minutes.
Connect to the apps your users rely on without maintaining the infrastructure that keeps it working.
Corsair is the unified integration layer for your agents. Connect your Corsair instance to your agent and immediately get access to every integration. Your agent never sees the credentials, and you control exactly what it can do.
A Control Mechanism for AI Agent.
This document introduces .agentignore, a simple yet powerful way designed to give you precise control over which parts of your codebase AI agents and code assistants can access.
Mobile Verification Toolkit (MVT) is a tool to facilitate the consensual forensic analysis of Android and iOS devices, for the purpose of identifying traces of compromise.
Related contents:
-#537: Espionnage et recherche de compromission dans les environnements mobiles @ NoLimitSecu :fr:.
Mobile Security Analysis. Uncover the threats targeting your smartphones.
Shindan is a SaaS, mobile and desktop application, that detects compromissions and vulnerabilities on smartphones and tablets, without access to personal data. Get a quick and accurate diagnosis to protect your VIPs and collaborators.
Related contents:
-#537: Espionnage et recherche de compromission dans les environnements mobiles @ NoLimitSecu :fr:.
Risk analysis, from inherent to residual. the standalone, offline risk-analysis editor.
A standalone risk-analysis editor, built on a generic, configurable model: define your grid, enter risks and controls, and visualize the shift from inherent to residual risk – matrices, trajectories, action plan and report. The whole analysis fits in a single open .rae.json file.
asago (AI Safety And Governance Orchestration) is an open-source community that aims to automate the journey from AI governance policy to production-ready, safely deployed AI systems — bridging the gap between compliance teams, AI engineers, and infrastructure operators.
Related contents:
Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.
Suzaku (朱雀) — the "Vermilion Bird" that rules the southern heavens above the clouds — is a threat hunting and fast forensics timeline generator for cloud logs, written in memory-safe Rust. Think of Hayabusa but for cloud logs instead of Windows event logs, with native Sigma detection for AWS CloudTrail (Azure and GCP planned).
Among thousands of cloud API calls, Suzaku finds the attacks in the noise and gives you a DFIR timeline with only the events you need — plus summaries of attacker activity (source IPs, geo-location, regions, user agents) to pivot on.
An Active Directory security-assessment toolkit in Rust: a PingCastle-class auditor that maps a domain's attack paths — scored, graphed, and MITRE-tagged — then, for authorized red-team and research use, proves those paths end-to-end. One static binary, from Kali/Linux or Windows, on an embedded from-scratch DCE/RPC · NTLM · SMB2 · Kerberos stack (the "impacket for Rust" that didn't otherwise exist).
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
ADR (Agentic AI Detection and Response) is an enterprise security system for AI agents. It helps organizations secure employee-facing agents such as Cursor, Claude Code, and Codex, as well as customer-facing agents such as AI support agents.
An egress firewall for untrusted workloads.
iron-proxy is a single-binary egress firewall for workloads you don't fully trust. It enforces an allowlist on outbound HTTP and HTTPS, holds credentials so the workload never sees the real value, and records every request as structured JSON.
Deployment of an Active Directory Tier Model structure to support Tier 0, Tier 1, and Tier 2 objects.
Declarative PowerShell framework to deploy and audit an Active Directory Tier Model (OUs, Groups, Users, ACL Delegations, GPOs, ADMX, MSA/gMSA/dMSA Permissions, Windows LAPS Permissions) from a single version-controlled JSON configuration file. Supports idempotent re-runs, drift detection, and reproducible builds via pinned dependency versions.
An evolving recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested.
A curated pack of security skills for external reconnaissance, web applications, APIs, authentication, vulnerability validation, attack-path analysis, and reporting.
Access your docker socket safely as read-only, rootless and distroless.
What can I do with this? This image will run a proxy to access your docker socket as read-only. The exposed proxy socket is run as 1000:1000, not as root, although the image starts the proxy process as root to interact with the actual docker socket. There is also a TCP endpoint started at 2375 that will also proxy to the actual docker socket if needed.
Visibility into AI agent activity on endpoints, with on-device detection, optional pre-action blocking, and forensic reconstruction.
numbat observes supported desktop, CLI, IDE, and gateway agents through local hooks and plugins, OTLP/HTTP logs, and on-disk session artifacts. Live and at-rest activity is normalized into one event model and evaluated by the same CEL rule engine. Detection runs locally; records can be written to stdout or a local file and optionally delivered over HTTP.
Orchestrate AI agents to find real vulnerabilities in code.
An open-source, self-hosted security research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment.
Give the agent a cage, not your keys.
Give the agent a cage, not your keys. One-command Docker sandbox for AI coding agents: full autonomous permissions, per-project isolation, your host stays untouched.
The Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by agents.
A high-performance hook for AI coding agents that blocks destructive commands before they execute, protecting your work from accidental deletion across Claude Code, Codex CLI, Gemini CLI, Copilot CLI, VS Code Copilot Chat, Cursor, Hermes Agent, Grok (xAI), and related tools.
Deploy Cloud Native Applications inside Confidential Enclaves Protect containers while they are running using confidential computing and hardware-backed isolation.
Confidential Containers is an open source community working to enable cloud native confidential computing by leveraging Trusted Execution Environments to protect containers and data.
Related contents:
Lightweight & Fast Security Scanner for React Native & Expo.
A zero-configuration security scanner for React Native and Expo applications that detects vulnerabilities, hardcoded secrets, and security misconfigurations with a single command.
Dusseldorf is an out-of-band security tool to help in security research.
Dusseldorf is a private, customizable out-of-band application security testing (OAST) platform. It captures inbound network traffic across multiple protocols and lets you craft automated responses for security validation workflows.
It is designed for security professionals who need controlled infrastructure to detect and validate out-of-band vulnerabilities such as SSRF, XSS, SSTI, XXE, and related classes of defects.
Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.
ADPathFinder is an attack mapping tool for pentesters and red teamers. It analyses SharpHound data and unifies it with OpenGraph plugins to surface attack paths to high-value targets such as Domain Admins and Domain Controllers, starting from low-privileged users and computers. MSSQLHound and ConfigManBearPig are supported natively, extending coverage across AD, ADCS, SCCM, and MSSQL.
Related contents:
A Mastodon instance for info/cyber security-minded people.
Security scanner for VS Code extensions.
Security scanner for VS Code extensions. Detects malicious extensions before installation by analyzing code patterns, indicators of compromise, and known malware signatures.
A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings.
A coding-agent skill that turns your agent into a security auditor. It orchestrates multiple parallel agents through a six-phase pipeline -- recon, hunting, validation, reporting, structured output, and independent verification -- to find exploitable vulnerabilities with real impact.
Related contents:
Modular Go framework for attack surface management, reconnaissance, and vulnerability scanning.
NOX is a modular, Go based attack surface management and vulnerability scanning framework. It ships with 300 built in modules covering OSINT, subdomain enumeration, DNS, port scanning, web fingerprinting, and deep active vulnerability testing across injection, authentication, authorization, client side, cloud, API, and business logic vulnerability classes.
USB kill switch + dead man's switch for Linux server: automatic LUKS header wipe on USB disconnection or operator inactivity.
A better alternative to sudo(-rs)/su • ⚡ Blazing fast • 🛡️ Memory-safe • 🔐 Security-oriented.
RootAsRole is a Linux/Unix privilege delegation tool based on Role-Based Access Control (RBAC). It empowers administrators to assign precise privileges — not full root — to users and commands.
GitHub Actions security scanner: pin actions to SHAs, detect script injection, audit permissions. Fix supply chain vulnerabilities.
Secure your GitHub Actions workflows against supply chain attacks. Detects unpinned actions (the tj-actions attack vector), dangerous permissions, and script injection — all in one scan.
performant, safer npm package alternatives.
type a package name. we'll tell you what you don't need. The module replacements project is a community-driven effort to map replaceable npm packages to their native or more performant alternatives.
This website serves as a searchable, interactive catalog of these module replacements, allowing you to easily find and adopt better alternatives for your projects.
Related contents:
Malicious traffic detection system.
Maltrail is a malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails, along with static trails compiled from various AV reports and custom user defined lists, where a trail can be anything from a domain name (e.g. zvpprsensinaix.com for Banjori malware), URL (e.g. hXXp://109.162.38.120/harsh02.exe for known malicious executable), IP address (e.g. 185.130.5.231 for known attacker) or HTTP User-Agent header value (e.g. sqlmap for automatic SQL injection and database takeover tool). Also, it uses (optional) advanced heuristic mechanisms that can help in the discovery of unknown threats (e.g. new malware).
A Fun, Live View of Multi-Protocol Internet Break-in Attempts.
Live Honeypot Dashboard for SSH, Telnet, FTP, RDP, SMB, SIP, HTTP, and SMTP Attacks.
autonomous red teaming platform; multi-agent offensive-security meta-harness.
A multi-agent offensive-security framework, built to turn the AI coding agent you already run into a zero-day hunter.
Founded in 2015, this upstream Linux kernel project starts with the premise that kernel bugs have a very long lifetime, and that the kernel must be designed in ways to protect against these flaws. We must think of security beyond fixing bugs. As a community, we already find and fix individual bugs via static checkers (compiler flags, smatch, coccinelle, coverity, CodeQL) and dynamic checkers (kernel configs, syzkaller, KASan, trinity). Those efforts are important and on-going, but if we want to protect our billion Android phones, our cars, the International Space Station, and everything else running Linux, we must get proactive defensive technologies built into the upstream Linux kernel. We need the kernel to fail safely, instead of just running safely.
Related contents:
Application-Level Face Recognition Lock for macOS.
World's first Face Authentication enabled MacOS App-locker. Unlock your Mac apps using Face , TouchID or password. Completely local and encrypted - your data never leaves your Mac.
Related contents: