bin3xish477 / ghast
GHAST (GitHub Actions Static Analysis Tool) is a tool to analyze the security posture of your GitHub Actions and its surrounding environment for common security vulnerabilities or missing security configuration.
☆17Updated last year
Alternatives and similar repositories for ghast:
Users that are interested in ghast are comparing it to the libraries listed below
- Tool to check the CloudTrail configuration and the services where trails are sent, to detect potential attacks to CloudTrail logging.☆13Updated 8 months ago
- ☆38Updated 10 months ago
- ☆42Updated 8 months ago
- ☆55Updated last year
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated last year
- ☆58Updated last year
- ☆13Updated last year
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆40Updated last year
- InfoSec OpenAI Examples☆19Updated last year
- Virtual Security Operations Center☆50Updated last year
- A PoC to Simulate Ransomware Attack on AWS Environment☆30Updated 4 months ago
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.☆30Updated 2 years ago
- An LLM and OCR based Indicator of Compromise Extraction Tool☆33Updated 2 months ago
- ☆90Updated 3 years ago
- ☆32Updated 6 months ago
- A public cloud security knowledgebase - https://www.secwiki.cloud/☆51Updated 3 months ago
- A web security research tool for DOM testing☆18Updated this week
- An example of a mis-configured Rails application release under MIT license.☆20Updated 2 years ago
- ☆33Updated 2 months ago
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆36Updated 4 months ago
- Do bulk whois lookups and get alerted on domains of interest.☆24Updated 6 months ago
- ☆17Updated 2 years ago
- 📚A curated list of product security resources.☆19Updated 2 years ago
- Docs: Vulnerability management aggregation of AppSec & OpSec (Tools Listing)☆30Updated last year
- A GitHub Actions Supply Chain CTF / Goat☆17Updated 2 weeks ago
- A set of AWS resources for testing the Log4Shell vulnerability, deployable with terraform☆12Updated 3 years ago
- 🖇️ STRIDE vs. ASVS equivalence table☆75Updated 5 months ago
- This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits containing potential secret or interesting…☆45Updated 6 months ago
- Blogpost series showcasing interesting cloud - web app security bugs☆47Updated last year
- A simple script that generates an Excel friendly CSV file from an Amass JSON file.☆13Updated 2 years ago