synacktiv / action-octoscan
📦 A GitHub Action that performs a security scan of your GitHub Actions.
☆26Updated 6 months ago
Alternatives and similar repositories for action-octoscan:
Users that are interested in action-octoscan are comparing it to the libraries listed below
- ☆64Updated last week
- Nuclei plugins to audit Chrome extensions☆64Updated 9 months ago
- Burp Suite extension for testing Passkey systems.☆69Updated last month
- VM Lab for security☆9Updated last year
- A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.☆22Updated 6 months ago
- Outil de sécurité des architectures kubernetes avancées☆51Updated 6 months ago
- Collection of Docker honeypot logs from 2021 - 2024☆36Updated 7 months ago
- boostsecurityio/lotp☆124Updated 3 weeks ago
- A curated list of argument injection vectors☆41Updated 3 months ago
- A tool for quickly evaluating IAM permissions in AWS.☆57Updated last year
- Unicode Security Toolkit☆34Updated 7 months ago
- CaptainCredz is a modular and discreet password-spraying tool.☆109Updated this week
- ☆47Updated 10 months ago
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆64Updated 2 weeks ago
- ☆29Updated 3 weeks ago
- ☆14Updated 8 months ago
- Addon for BHCE☆45Updated last month
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalation☆103Updated last year
- ☆96Updated 2 weeks ago
- A multi-cloud DNS record scanner that aims to help cybersecurity/IT analysts identify dangling CNAME records in their cloud DNS services …☆49Updated 2 years ago
- GeoWordlists is a tool to generate wordlists of passwords containing cities at a defined distance around the client city.☆148Updated 3 months ago
- gubble is a tool designed to audit Google Workspace group settings. It analyzes settings such as who can join, view membership, post mess…☆55Updated 4 months ago
- TruffleHog Explorer, a user-friendly web-based tool to visualize and analyze data extracted using TruffleHog.☆38Updated 3 months ago
- Prototype of Full Agentic Application Security Testing, FAAST = SAST + DAST + LLM agents☆43Updated last week
- ☆40Updated 8 months ago
- ☆35Updated last month
- ☠️ Code for the Defcon Workshop☆23Updated 9 months ago
- Hijack a slack bot to phish your way in☆55Updated last month
- SOAPI - The OpenAPI Documentation Scanner☆37Updated 2 months ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated 2 months ago