synacktiv / action-octoscan
📦 A GitHub Action that performs a security scan of your GitHub Actions.
☆26Updated 3 months ago
Alternatives and similar repositories for action-octoscan:
Users that are interested in action-octoscan are comparing it to the libraries listed below
- ☆55Updated 2 months ago
- boostsecurityio/lotp☆112Updated this week
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆40Updated last year
- ☆42Updated 8 months ago
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆56Updated 2 weeks ago
- CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).☆104Updated last month
- Offensive Web is a documentation website about security research, difficult concepts, bypass and new exploitation techniques.☆24Updated 2 months ago
- Outil de sécurité des architectures kubernetes avancées☆48Updated 3 months ago
- GeoWordlists is a tool to generate wordlists of passwords containing cities at a defined distance around the client city.☆145Updated last week
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆190Updated last month
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalation☆102Updated last year
- Nuclei plugins to audit Chrome extensions☆63Updated 7 months ago
- CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to …☆123Updated 10 months ago
- A curated list of argument injection vectors☆40Updated 3 weeks ago
- VM Lab for security☆9Updated 11 months ago
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆36Updated 4 months ago
- This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits containing potential secret or interesting…☆45Updated 6 months ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated 2 months ago
- A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.☆21Updated 4 months ago
- Unicode Security Toolkit☆33Updated 4 months ago
- gubble is a tool designed to audit Google Workspace group settings. It analyzes settings such as who can join, view membership, post mess…☆41Updated last month
- A recon tool that uses ML to predict subdomains. Then returns those that resolve.☆49Updated last month
- A python module to explore the object tree to extract paths to interesting objects in memory.☆88Updated 3 weeks ago
- ☆40Updated 5 months ago
- Web interface to explore Suricata EVE outputs☆48Updated 2 months ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆31Updated last year
- A tool for quickly evaluating IAM permissions in AWS.☆57Updated last year
- Create tar/zip archives that try to exploit zipslip vulnerability.☆47Updated 5 months ago
- Additional active scan checks for BURP☆26Updated 4 months ago