Lists (11)
Sort Name ascending (A-Z)
Stars
Keep your coding skills sharp in the age of AI
Continuous infrastructure drift detection with historical tracking and notifications.
An AWS IAM Privilege Escalation Path Library
AI agent for autonomous cyber operations
Powerful yet simple to use screenshot software 🖥️ 📸
IAM Policy Autopilot is an open source static code analysis tool that helps you quickly create baseline AWS IAM policies that you can refine as your application evolves. This tool is available as a…
A modern static site generator by the Material for MkDocs team
Kingfisher is a blazingly fast and highly accurate tool for secret detection and live validation across files, Git repos, GitHub, GitLab, Azure Repos, BitBucket, Gitea, AWS S3, Docker images, Jira,…
Insights into the world's most critical open source software.
👋 Ever performed an action in the Microsoft admin portals like Entra or Intune and wished you knew how to script it? Graph X-Ray gives you 'X-ray vision'!
Recon via Terraform Plan PoC. For research and educational purposes only!
🎒 Token-Oriented Object Notation (TOON) – Compact, human-readable, schema-aware JSON for LLM prompts. Spec, benchmarks, TypeScript SDK.
Tokenex is a Go library that securely exchanges identity tokens for temporary cloud credentials, with built-in support for AWS, GCP, Azure, OCI, Kubernetes, and OAuth2.
A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS accounts.
OWASP Foundation web repository
A benchmark for prompt injection detection systems.
Proof of Concepts for malicious maintainers: How to Tamper with Releases built with GitHub Actions Worfklows, presented at fwd:cloudsec Europe 2025
Cartography is a Python tool that consolidates infrastructure assets and the relationships between them in an intuitive graph view powered by a Neo4j database.
A framework for building high gravity communities 🪐
An index of publicly available and open-source threat detection rulesets.
A CLI to create short-lived (8 hours) GitHub App User Access Token for secure local development
Writeups for the CloudVillage CTF at DEFCON33
A list of hand-picked dangerous AWS IAM actions that will help us evaluate AWS-related security risks and conduct IAM security audits.