aws / http-desync-guardianLinks
Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).
☆272Updated 5 years ago
Alternatives and similar repositories for http-desync-guardian
Users that are interested in http-desync-guardian are comparing it to the libraries listed below
Sorting:
- A command line interface for Amazon EBS snapshots☆249Updated last week
- Rust libraries and tools for using and generating TUF repositories☆217Updated last week
- DEPRECATED - web security checklist for Firefox Services☆78Updated 5 years ago
- A production-friendly malware scanner for your AWS cloud☆200Updated 4 years ago
- Static analysis for CloudFormation templates to identify common misconfiguration☆56Updated 3 years ago
- ☆143Updated last month
- No need for IAM users when we have Yubikeys☆158Updated 3 years ago
- Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).☆143Updated 8 months ago
- k8s audit repo☆229Updated 6 years ago
- AWS Metadata Proxy for protection against SSRF☆68Updated 5 years ago
- OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws☆328Updated last year
- Resource types that can be publicly exposed on AWS☆329Updated 3 years ago
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.☆64Updated 6 years ago
- Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)☆447Updated 2 years ago
- for AWS Security material☆249Updated 3 years ago
- List of vendors that do not allow IMDSv2 enforcement☆143Updated last year
- Framework for Testing WAFs (FTW!)☆135Updated last year
- Security aspects of AWS products for the Security Specialist certification☆211Updated 3 years ago
- Security scanning & static analysis tool☆93Updated last year
- ☆252Updated 5 years ago
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆74Updated last year
- Research on the enumeration of IAM permissions without logging to CloudTrail☆61Updated 4 years ago
- Example detection of compromise credentials in AWS☆122Updated 7 years ago
- CLI wrapper around aws-encryption-sdk-python☆80Updated last month
- Temporary Credential Service☆173Updated last month
- Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.☆554Updated 6 months ago
- An attack/exploit Detector that utilizes Polymorphism and Diversity☆30Updated 3 years ago
- ☆83Updated 6 years ago
- OWASP Serverless Top 10☆217Updated 4 years ago
- Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.☆162Updated last month