wspr-ncsu / github-actions-security-analysis
☆10Updated 10 months ago
Related projects ⓘ
Alternatives and complementary repositories for github-actions-security-analysis
- A small library to alter AWS API requests; Used for fuzzing research☆21Updated last year
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated 3 months ago
- Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool☆25Updated 3 years ago
- ☆14Updated last year
- python3 scripts to help with aws triage needs☆15Updated 2 years ago
- A meta-database collecting resources that compile lists of breaches☆18Updated 3 weeks ago
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.☆49Updated 2 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Updated 2 years ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆22Updated 4 months ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆45Updated 2 months ago
- A PoC to Simulate Ransomware Attack on AWS Environment☆28Updated last month
- Modron - Cloud security compliance☆33Updated this week
- Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding In…☆18Updated 3 years ago
- Fun tools around the EBS Direct API☆18Updated 3 years ago
- HoneyZure is a honeypot tool specifically designed for Azure environments, fully provisioned through Terraform. It leverages a Log Analyt…☆16Updated 5 months ago
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Updated last year
- ☆25Updated 3 years ago
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆27Updated 9 months ago
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- A steampipe plugin to query projectdiscovery.io tools.☆26Updated 4 months ago
- Sniff and attack networks that use IP-in-IP or VXLAN encapsulation protocols.☆21Updated 2 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆57Updated last year
- An Evil OIDC Server☆51Updated 2 years ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆39Updated 11 months ago
- ☆38Updated 5 months ago
- Konstellation is a configuration-driven CLI tool to enumerate cloud resources and store the data into Neo4j.☆19Updated last year
- ☆40Updated last month