Supply Chain Security Research - Living Off The Pipeline tools
☆163Jul 31, 2026Updated 2 months ago
Alternatives and similar repositories for lotp
Users that are interested in lotp are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆15Sep 22, 2025Updated last year
- poutine, a supply chain vulnerability scanner for build pipelines☆522Updated this week
- bagel, a CLI that inventories security-relevant metadata on developer workstations☆202Updated this week
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆384Sep 17, 2026Updated 3 weeks ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆21Mar 9, 2025Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆377Jul 10, 2026Updated 2 months ago
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆173May 8, 2026Updated 5 months ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆44Jan 25, 2026Updated 8 months ago
- Supply Chain Security Research - Attack Trees☆11Jan 9, 2023Updated 3 years ago
- A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.☆33Oct 13, 2024Updated last year
- How GitHub Actions workflows can be hacked☆190Aug 23, 2024Updated 2 years ago
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆273Mar 30, 2026Updated 6 months ago
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆592Oct 2, 2026Updated last week
- https://lolad-project.github.io/☆94Jan 2, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆40Aug 2, 2024Updated 2 years ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆152Aug 28, 2024Updated 2 years ago
- Living Off Security Tools☆67Aug 19, 2026Updated last month
- moniorg is a tool that leverages crt.sh website to monitor domains of a target☆48Apr 1, 2023Updated 3 years ago
- Scan GitHub repositories for potentially infected MSBuild project files☆17May 27, 2025Updated last year
- ☆194Apr 16, 2025Updated last year
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆182Jul 29, 2026Updated 2 months ago
- ☆19Jul 30, 2024Updated 2 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.☆634Jun 2, 2026Updated 4 months ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆195Updated this week
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆40Sep 25, 2024Updated 2 years ago
- Mythic C2 Profile that allows agents to communicate over GitHub☆19Jan 14, 2025Updated last year
- A GitHub Actions Supply Chain CTF / Goat☆29Apr 13, 2026Updated 5 months ago
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆90Jan 28, 2024Updated 2 years ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆129Sep 17, 2026Updated 3 weeks ago
- LotL RMM☆406Updated this week
- ☆28May 6, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Data about all known supply-chain attacks through history☆80Aug 12, 2026Updated last month
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆1,229Updated this week
- ☆148Aug 10, 2026Updated last month
- bootloaders.io is a curated list of known malicious bootloaders for various operating systems. The project aims to assist security profes…☆81Aug 31, 2023Updated 3 years ago
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆19Sep 2, 2026Updated last month
- A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE☆121Updated this week
- ☆95Dec 15, 2025Updated 9 months ago