Supply Chain Security Research - Living Off The Pipeline tools
☆160May 7, 2026Updated 2 months ago
Alternatives and similar repositories for lotp
Users that are interested in lotp are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆16Sep 22, 2025Updated 9 months ago
- poutine, a supply chain vulnerability scanner for build pipelines☆490Jul 9, 2026Updated last week
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆21Mar 9, 2025Updated last year
- bagel, a CLI that inventories security-relevant metadata on developer workstations☆181Jul 13, 2026Updated last week
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆367Jun 27, 2026Updated 3 weeks ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆367Jul 10, 2026Updated last week
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆167May 8, 2026Updated 2 months ago
- moniorg is a tool that leverages crt.sh website to monitor domains of a target☆48Apr 1, 2023Updated 3 years ago
- ☆18Jul 30, 2024Updated last year
- How GitHub Actions workflows can be hacked☆186Aug 23, 2024Updated last year
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆562Jul 13, 2026Updated last week
- Supply Chain Security Research - Attack Trees☆10Jan 9, 2023Updated 3 years ago
- ☆193Apr 16, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆40Sep 25, 2024Updated last year
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.☆611Jun 2, 2026Updated last month
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆152Aug 28, 2024Updated last year
- ☆40Aug 2, 2024Updated last year
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆125Jun 20, 2026Updated last month
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆172Jul 14, 2026Updated last week
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆19Jul 13, 2026Updated last week
- ☆28May 6, 2024Updated 2 years ago
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆270Mar 30, 2026Updated 3 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.☆14Jan 15, 2025Updated last year
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆44Jan 25, 2026Updated 5 months ago
- python3 scripts to help with aws triage needs☆15Feb 11, 2022Updated 4 years ago
- ☆233Jun 10, 2026Updated last month
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆114Nov 13, 2024Updated last year
- Data about all known supply-chain attacks through history☆76Jun 28, 2026Updated 3 weeks ago
- A tool to uncover undocumented APIs from the AWS Console.☆120Mar 16, 2026Updated 4 months ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆166Updated this week
- GTFO Command Line Interface for easy binaries search commands that can be used to bypass local security restrictions in misconfigured sys…☆18Jan 26, 2026Updated 5 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- A GitHub Actions Supply Chain CTF / Goat☆28Apr 13, 2026Updated 3 months ago
- Scan GitHub repositories for potentially infected MSBuild project files☆17May 27, 2025Updated last year
- ☆76Mar 19, 2025Updated last year
- A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.☆30Oct 13, 2024Updated last year
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆90Jan 28, 2024Updated 2 years ago
- Unauthenticated enumeration of AWS, Azure, and GCP Principals☆292Jun 10, 2026Updated last month
- Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.☆28Feb 8, 2023Updated 3 years ago