security
A.I.G (AI-Infra-Guard) is a comprehensive, intelligent, and user-friendly AI Red Teaming security testing platform developed by Tencent Zhuque Lab.
Detection Skills is an open standard for the Agentic SOC, that transforms static detections into agentic workflows. Designed and used by Cyber Defense Engineers, it brings the best your team can do - to every alert.
Reference architecture for AI agents that propose actions but cannot authorize them — immutable intent capture, an independent Decionis policy verdict (ALLOW/ESCALATE/BLOCK), verified human approval, and a SafeExecutor that consumes a single-use intent-bound grant.
Varnish Orca is a Virtual Registry Manager: a fast pull-through cache for artifact registries. Control which packages reach your developers, pipelines, and agents.
Deploy it close to your developers and CI/CD pipelines to reduce build times and egress costs.
Related contents:
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
Open Source Integration Layer for AI Agents. Add any integration in minutes.
Connect to the apps your users rely on without maintaining the infrastructure that keeps it working.
Corsair is the unified integration layer for your agents. Connect your Corsair instance to your agent and immediately get access to every integration. Your agent never sees the credentials, and you control exactly what it can do.
A Control Mechanism for AI Agent.
This document introduces .agentignore, a simple yet powerful way designed to give you precise control over which parts of your codebase AI agents and code assistants can access.
Mobile Verification Toolkit (MVT) is a tool to facilitate the consensual forensic analysis of Android and iOS devices, for the purpose of identifying traces of compromise.
Related contents:
-#537: Espionnage et recherche de compromission dans les environnements mobiles @ NoLimitSecu :fr:.
Mobile Security Analysis. Uncover the threats targeting your smartphones.
Shindan is a SaaS, mobile and desktop application, that detects compromissions and vulnerabilities on smartphones and tablets, without access to personal data. Get a quick and accurate diagnosis to protect your VIPs and collaborators.
Related contents:
-#537: Espionnage et recherche de compromission dans les environnements mobiles @ NoLimitSecu :fr:.
Risk analysis, from inherent to residual. the standalone, offline risk-analysis editor.
A standalone risk-analysis editor, built on a generic, configurable model: define your grid, enter risks and controls, and visualize the shift from inherent to residual risk – matrices, trajectories, action plan and report. The whole analysis fits in a single open .rae.json file.
asago (AI Safety And Governance Orchestration) is an open-source community that aims to automate the journey from AI governance policy to production-ready, safely deployed AI systems — bridging the gap between compliance teams, AI engineers, and infrastructure operators.
Related contents:
Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.
Suzaku (朱雀) — the "Vermilion Bird" that rules the southern heavens above the clouds — is a threat hunting and fast forensics timeline generator for cloud logs, written in memory-safe Rust. Think of Hayabusa but for cloud logs instead of Windows event logs, with native Sigma detection for AWS CloudTrail (Azure and GCP planned).
Among thousands of cloud API calls, Suzaku finds the attacks in the noise and gives you a DFIR timeline with only the events you need — plus summaries of attacker activity (source IPs, geo-location, regions, user agents) to pivot on.
An Active Directory security-assessment toolkit in Rust: a PingCastle-class auditor that maps a domain's attack paths — scored, graphed, and MITRE-tagged — then, for authorized red-team and research use, proves those paths end-to-end. One static binary, from Kali/Linux or Windows, on an embedded from-scratch DCE/RPC · NTLM · SMB2 · Kerberos stack (the "impacket for Rust" that didn't otherwise exist).
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
ADR (Agentic AI Detection and Response) is an enterprise security system for AI agents. It helps organizations secure employee-facing agents such as Cursor, Claude Code, and Codex, as well as customer-facing agents such as AI support agents.
An egress firewall for untrusted workloads.
iron-proxy is a single-binary egress firewall for workloads you don't fully trust. It enforces an allowlist on outbound HTTP and HTTPS, holds credentials so the workload never sees the real value, and records every request as structured JSON.
Deployment of an Active Directory Tier Model structure to support Tier 0, Tier 1, and Tier 2 objects.
Declarative PowerShell framework to deploy and audit an Active Directory Tier Model (OUs, Groups, Users, ACL Delegations, GPOs, ADMX, MSA/gMSA/dMSA Permissions, Windows LAPS Permissions) from a single version-controlled JSON configuration file. Supports idempotent re-runs, drift detection, and reproducible builds via pinned dependency versions.
An evolving recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested.
A curated pack of security skills for external reconnaissance, web applications, APIs, authentication, vulnerability validation, attack-path analysis, and reporting.
Access your docker socket safely as read-only, rootless and distroless.
What can I do with this? This image will run a proxy to access your docker socket as read-only. The exposed proxy socket is run as 1000:1000, not as root, although the image starts the proxy process as root to interact with the actual docker socket. There is also a TCP endpoint started at 2375 that will also proxy to the actual docker socket if needed.
Visibility into AI agent activity on endpoints, with on-device detection, optional pre-action blocking, and forensic reconstruction.
numbat observes supported desktop, CLI, IDE, and gateway agents through local hooks and plugins, OTLP/HTTP logs, and on-disk session artifacts. Live and at-rest activity is normalized into one event model and evaluated by the same CEL rule engine. Detection runs locally; records can be written to stdout or a local file and optionally delivered over HTTP.
Orchestrate AI agents to find real vulnerabilities in code.
An open-source, self-hosted security research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment.
Give the agent a cage, not your keys.
Give the agent a cage, not your keys. One-command Docker sandbox for AI coding agents: full autonomous permissions, per-project isolation, your host stays untouched.
The Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by agents.
A high-performance hook for AI coding agents that blocks destructive commands before they execute, protecting your work from accidental deletion across Claude Code, Codex CLI, Gemini CLI, Copilot CLI, VS Code Copilot Chat, Cursor, Hermes Agent, Grok (xAI), and related tools.
Deploy Cloud Native Applications inside Confidential Enclaves Protect containers while they are running using confidential computing and hardware-backed isolation.
Confidential Containers is an open source community working to enable cloud native confidential computing by leveraging Trusted Execution Environments to protect containers and data.
Related contents:
Lightweight & Fast Security Scanner for React Native & Expo.
A zero-configuration security scanner for React Native and Expo applications that detects vulnerabilities, hardcoded secrets, and security misconfigurations with a single command.
Dusseldorf is an out-of-band security tool to help in security research.
Dusseldorf is a private, customizable out-of-band application security testing (OAST) platform. It captures inbound network traffic across multiple protocols and lets you craft automated responses for security validation workflows.
It is designed for security professionals who need controlled infrastructure to detect and validate out-of-band vulnerabilities such as SSRF, XSS, SSTI, XXE, and related classes of defects.
Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.
ADPathFinder is an attack mapping tool for pentesters and red teamers. It analyses SharpHound data and unifies it with OpenGraph plugins to surface attack paths to high-value targets such as Domain Admins and Domain Controllers, starting from low-privileged users and computers. MSSQLHound and ConfigManBearPig are supported natively, extending coverage across AD, ADCS, SCCM, and MSSQL.
Related contents:
A Mastodon instance for info/cyber security-minded people.
Security scanner for VS Code extensions.
Security scanner for VS Code extensions. Detects malicious extensions before installation by analyzing code patterns, indicators of compromise, and known malware signatures.
A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings.
A coding-agent skill that turns your agent into a security auditor. It orchestrates multiple parallel agents through a six-phase pipeline -- recon, hunting, validation, reporting, structured output, and independent verification -- to find exploitable vulnerabilities with real impact.
Related contents:
Modular Go framework for attack surface management, reconnaissance, and vulnerability scanning.
NOX is a modular, Go based attack surface management and vulnerability scanning framework. It ships with 300 built in modules covering OSINT, subdomain enumeration, DNS, port scanning, web fingerprinting, and deep active vulnerability testing across injection, authentication, authorization, client side, cloud, API, and business logic vulnerability classes.
USB kill switch + dead man's switch for Linux server: automatic LUKS header wipe on USB disconnection or operator inactivity.
A better alternative to sudo(-rs)/su • ⚡ Blazing fast • 🛡️ Memory-safe • 🔐 Security-oriented.
RootAsRole is a Linux/Unix privilege delegation tool based on Role-Based Access Control (RBAC). It empowers administrators to assign precise privileges — not full root — to users and commands.
GitHub Actions security scanner: pin actions to SHAs, detect script injection, audit permissions. Fix supply chain vulnerabilities.
Secure your GitHub Actions workflows against supply chain attacks. Detects unpinned actions (the tj-actions attack vector), dangerous permissions, and script injection — all in one scan.
performant, safer npm package alternatives.
type a package name. we'll tell you what you don't need. The module replacements project is a community-driven effort to map replaceable npm packages to their native or more performant alternatives.
This website serves as a searchable, interactive catalog of these module replacements, allowing you to easily find and adopt better alternatives for your projects.
Related contents:
Malicious traffic detection system.
Maltrail is a malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails, along with static trails compiled from various AV reports and custom user defined lists, where a trail can be anything from a domain name (e.g. zvpprsensinaix.com for Banjori malware), URL (e.g. hXXp://109.162.38.120/harsh02.exe for known malicious executable), IP address (e.g. 185.130.5.231 for known attacker) or HTTP User-Agent header value (e.g. sqlmap for automatic SQL injection and database takeover tool). Also, it uses (optional) advanced heuristic mechanisms that can help in the discovery of unknown threats (e.g. new malware).
A Fun, Live View of Multi-Protocol Internet Break-in Attempts.
Live Honeypot Dashboard for SSH, Telnet, FTP, RDP, SMB, SIP, HTTP, and SMTP Attacks.
autonomous red teaming platform; multi-agent offensive-security meta-harness.
A multi-agent offensive-security framework, built to turn the AI coding agent you already run into a zero-day hunter.
Founded in 2015, this upstream Linux kernel project starts with the premise that kernel bugs have a very long lifetime, and that the kernel must be designed in ways to protect against these flaws. We must think of security beyond fixing bugs. As a community, we already find and fix individual bugs via static checkers (compiler flags, smatch, coccinelle, coverity, CodeQL) and dynamic checkers (kernel configs, syzkaller, KASan, trinity). Those efforts are important and on-going, but if we want to protect our billion Android phones, our cars, the International Space Station, and everything else running Linux, we must get proactive defensive technologies built into the upstream Linux kernel. We need the kernel to fail safely, instead of just running safely.
Related contents:
Application-Level Face Recognition Lock for macOS.
World's first Face Authentication enabled MacOS App-locker. Unlock your Mac apps using Face , TouchID or password. Completely local and encrypted - your data never leaves your Mac.
Related contents:
La démarche d’amélioration cyber, thématique et progressive (Dalton) est un projet de la division assistance technique (DAT) visant à recenser et organiser les mesures techniques permettant d’améliorer la sécurité des SI.
La doctrine de l'ANSSI est un terme parapluie regroupant l'ensemble des recommandations et positions de l'ANSSI. Elle est diffusée au travers de guides (les guides techniques, les "Fondamentaux", les "Essentiels"), de billets et notes techniques sur le site du CERT-FR, de présentations réalisées dans diverses instances publiques et privées, ou de publications open source.
The Security Profiles Operator (SPO) is an out-of-tree Kubernetes enhancement which aims to make it easier to create and use SELinux, seccomp and AppArmor security profiles in Kubernetes clusters.
Related contents:
An alternative to Howdy.
While Windows Hello provides a seamless multi-modal biometric experience (Face, Fingerprint, PIN) on Windows 11, Linux has historically lacked a modern, unified equivalent. The most well-known project in this space, Howdy, focuses exclusively on facial recognition and has not seen significant updates in recent years.
Biopass was developed by @phucvinh57 and @thaitran24 to fill this gap, providing a fast, secure, and modern biometric suite that goes beyond just face ID.
Related contents:
The OWASP Gen AI Security Project is an OWASP Flagship Project and global, open-source initiative dedicated to identifying, mitigating, and documenting security and safety risks associated with generative AI technologies, including large language models (LLMs), agentic AI systems, and AI-driven applications. Our mission is to empower organizations, security professionals, AI practitioners, and policymakers with comprehensive, actionable guidance and tools to ensure the secure development, deployment, and governance of generative AI systems.
Related contents:
Autonomous Security for the AI Era.
Open-source AI hackers to find and fix your app’s vulnerabilities. Strix are autonomous AI agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proof-of-concepts. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools.
Related contents:
Scan. Understand. Fix. Free, local-first JS/TS vulnerability scanner.
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
Most security tools are built around pipelines, not developers. CVE Lite CLI scans your lockfile locally in seconds, explains the dependency path, and tells you what to update before you push.
Related contents:
AI-Native Vulnerability Management.
AISLE finds, fixes, and verifies vulnerabilities autonomously – proven on the world's most audited codebases. Deploy anywhere: cloud, on-prem, or fully air-gapped.
Related contents:
Deploy bagel to developer Macs via macOS PKG and surface secret-scanning results in Fleet.
fleebag packages the bagel open-source secret scanner into a macOS installer (.pkg) that runs automatically on developer laptops via a LaunchAgent. Scan results are written as JSON and queried by Fleet's osquery agent, letting you see detected secrets across your entire fleet and enforce a compliance policy — all without touching each machine manually.
Related contents:
Les fiches réflexes d’InterCERT France sont mises à disposition de toutes les structures susceptibles d’être confrontées à un incident de cybersécurité. Qu’il s’agisse d’une entreprise, d’une administration, d’un opérateur essentiel ou d’une PME, ces ressources visent à renforcer la capacité de réaction de chacun.
A collection & lists of intel and usernames scraped from various cybercrime sources & forums. DarkForums, HackForums, Patched, Cracked, BreachForums, OGUser, XSS, Dread, & more.
Related contents:
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.
Generate realistic synthetic security logs for cybersecurity threat hunting training and research.
Related contents:
An modular asset discovery framework written in python to automate the repeating manual work.
Cygor is a modular asset discovery framework that brings scanning, parsing, and service enumeration together in one workflow. It replaces the patchwork of separate tools with an automated process that handles discovery, enrichment, and targeted enumeration seamlessly — reducing manual overhead and letting you focus on results instead of tool management.
Related contents:
A reference implementation for autonomous vulnerability discovery and remediation with Claude.
Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize.
A Claude Code skill bundle for bug hunting and external red-team work - 51 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 vulnerability classes, plus enterprise identity + infrastructure attack matrices.
Open-source hospital crisis management platform — multi-site, multi-language.
It is a complete, mature, ready-to-deploy platform that gives crisis directors, CISOs, medical coordinators, and supervisors the structured information they need — without requiring a cloud, a vendor contract, or a six-month integration project.
Related contents:
Falco-powered policy and visibility layer for AI coding agents.
Prempti brings Falco to the world of AI coding agents. It gives you guardrails that can deny or ask for confirmation on unwanted behaviors, plus real-time visibility into every tool call your coding agent makes — shell commands, file writes, reads, API calls. Both are driven by Falco rules you can customize to fit your workflow.
RAMPART: Risk Assessment & Measurement Platform for Agentic Red Teaming.
RAMPART is a pytest-native safety testing framework for agentic AI applications. You write tests that attack or probe your agent, and RAMPART orchestrates the interaction, evaluates the outcome, and reports the results.
OpenGraph Collector for Tailscale.
TailscaleHound is a BloodHound OpenGraph collector for Tailscale. It collects tailnet users, devices, groups, tags, ACLs, grants, SSH rules, routes, app connectors, services, invites, webhooks, and related control-plane metadata, then emits a BloodHound-compatible OpenGraph JSON file.
Think EDR, but for CI/CD Pipelines. Open-source eBPF-powered runtime security sensor for GitHub Actions and GitLab CI/CD.