Supply Chain Security Research - Living Off The Pipeline tools
☆161Jul 31, 2026Updated last week
Alternatives and similar repositories for lotp
Users that are interested in lotp are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆15Sep 22, 2025Updated 10 months ago
- poutine, a supply chain vulnerability scanner for build pipelines☆503Jul 9, 2026Updated last month
- bagel, a CLI that inventories security-relevant metadata on developer workstations☆190Jul 21, 2026Updated 2 weeks ago
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆373Updated this week
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆21Mar 9, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆370Jul 10, 2026Updated last month
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆169May 8, 2026Updated 3 months ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆44Jan 25, 2026Updated 6 months ago
- Supply Chain Security Research - Attack Trees☆10Jan 9, 2023Updated 3 years ago
- A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.☆33Oct 13, 2024Updated last year
- How GitHub Actions workflows can be hacked☆185Aug 23, 2024Updated last year
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆273Mar 30, 2026Updated 4 months ago
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆568Jul 20, 2026Updated 3 weeks ago
- https://lolad-project.github.io/☆92Jan 2, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆40Aug 2, 2024Updated 2 years ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆152Aug 28, 2024Updated last year
- moniorg is a tool that leverages crt.sh website to monitor domains of a target☆48Apr 1, 2023Updated 3 years ago
- Living Off Security Tools☆64Nov 23, 2025Updated 8 months ago
- Scan GitHub repositories for potentially infected MSBuild project files☆17May 27, 2025Updated last year
- ☆193Apr 16, 2025Updated last year
- ☆18Jul 30, 2024Updated 2 years ago
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆177Jul 29, 2026Updated last week
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.☆615Jun 2, 2026Updated 2 months ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆176Updated this week
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆40Sep 25, 2024Updated last year
- A GitHub Actions Supply Chain CTF / Goat☆28Apr 13, 2026Updated 3 months ago
- Mythic C2 Profile that allows agents to communicate over GitHub☆19Jan 14, 2025Updated last year
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆90Jan 28, 2024Updated 2 years ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆127Jun 20, 2026Updated last month
- LotL RMM☆386Jul 15, 2026Updated 3 weeks ago
- ☆28May 6, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Data about all known supply-chain attacks through history☆78Jul 28, 2026Updated 2 weeks ago
- ☆143Jun 18, 2026Updated last month
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆1,179Updated this week
- bootloaders.io is a curated list of known malicious bootloaders for various operating systems. The project aims to assist security profes…☆82Aug 31, 2023Updated 2 years ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆19Aug 3, 2026Updated last week
- A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE☆117Aug 3, 2026Updated last week
- ☆93Dec 15, 2025Updated 7 months ago