testifysec / solarsploit
Red team tool that emulates the SolarWinds CI compromise attack vector.
☆22Updated 8 months ago
Related projects ⓘ
Alternatives and complementary repositories for solarsploit
- go-ima is a tool that checks if a file has been tampered with. It is useful in ensuring integrity in CI systems☆13Updated last year
- Adversary emulation for EDR/SIEM testing (macOS/Linux)☆37Updated 9 months ago
- ☆24Updated 6 months ago
- An query language and interactive tooling to work with SBOM data.☆14Updated last month
- Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster☆35Updated 2 years ago
- TACOS framework structural details☆20Updated 11 months ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- K8s API Honeypot with Active Defense Capabilities☆39Updated 10 months ago
- ☆20Updated 6 months ago
- a tool to audit the istio service mesh☆173Updated 3 years ago
- Protect your Cloud Native Applications running on Kubernetes from malicious attacks with pre-registered source code, pre-registered runti…☆54Updated 6 months ago
- Go implementation of witness☆26Updated this week
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆94Updated 6 months ago
- ☆24Updated last year
- ☆51Updated 8 months ago
- Kubernetes offensive framework built in eBPF☆35Updated last year
- egrets monitors egress☆45Updated 4 years ago
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆22Updated this week
- Generative and mutative fuzzer for Kubernetes admission controller chains by automatically parsing the cluster api specification.☆70Updated last year
- ☆9Updated 7 months ago
- Automated testing, generation & manipulation of #osquery packs☆70Updated last month
- Integrates Spiffe and Vault to have secretless authentication☆85Updated this week
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated last week
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Updated last year
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆30Updated 10 months ago
- Manage a directory of binaries without a package manager☆21Updated 5 months ago
- A repository to store Rad Fingerprinting data.☆23Updated 3 months ago
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆27Updated 8 months ago
- Darkbit Cloud Security Tools☆25Updated 4 years ago
- Kubernetes Unhinged Shell 😎☆45Updated 2 years ago