
prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Deep learning framework for object detection, segmentation, classification, pose estimation, and tracking using pre-trained YOLO models and…

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…


Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Deep learning framework for object detection, segmentation, classification, pose estimation, and tracking using pre-trained YOLO models and…

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.


Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…


AD CS exploitation related stuff goes here

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

This repository contains the scanner component for Greenbone Community Edition.

Defense framework enforcing routed origin policy to prevent indirect prompt injection in tool-using LLM agents, with deterministic origin checks and…

Black-box attack framework that hijacks reasoning in agentic retrieval-augmented generation systems by injecting poisoned documents, with support for…

Research implementation of a poisoning attack against retrieval-augmented language models using camouflaged documents to evade filtering defenses and…

Benchmark for evaluating AI agent safety against attacks embedded in skill-facing context, with 155 cases across 6 risk domains, measuring task…

No-open firmware exploit for the Wyze WLPA19CV2 color bulb

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

A helper script for unpacking and decompiling EXEs compiled from python code.