Software Supply Chain Offensive Security. Vulnerability research and DevSecOps OG.
DevSecOps-Playbook. This is a step-by-step guide to implementing a DevSecOps program for any size organization
2kgimmepatz. Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams
43undelete. This JavaScript CLI "undeletes' packages that have been removed from the NPM registry
33nextjs-CVE-2025-29927. A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability
19DEFCON33-Workshop. DEFCON 33 Workshop - Open Source Malware 101 - Everything you always wanted to know about npm malware (and more)
16MALOSS. MALOSS scans package manifest files for malicious software packages and libraries
10commit-audit. Shell script that checks if git commits are signed
10super-confused. Super-confused is a next-gen dependency confusion tool.
10git-hunter. Find threats in your source code
66mile. About me!
6tvpo. Target, Value, Patterns and Objectives (TVPO) - A flexible threat modelling framework for the software supply chain
5awesome-cicd-attacks. Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
2npm-increaser-downloads. A tool to promote your npm packages and boost their download counts through automated strategies.
2awesome-api-security. A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
2ami_finder. Find your ami_id's for all regions for your products in the AWS Marketplace
2panda-mirror. Identify what Chinese NPM mirrors are caching malicious packages
1not-so-standard-package. Detection of Zero Hour Malicious Packages via ML
1awesome-software-supply-chain-security. A compilation of resources in the software supply chain security domain, with emphasis on open source
1CodeReviewWorkshop. Materials for "The Art of Finding Security Vulnerabilities in Code" workshop
1CY4740FinalProject. Final Project for CY4740 Network Security
1CloudShovel. A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where we scanned 20k+ public AMIs.
1vps-attack-box. Generic Ubuntu or CentOS boxes built for offensive or OSINT work deployed in your favorite VPS provider
1merlin. Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
1OSCAR. A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain
1BlackMass. A recon tool optimized for mass scanning
1spdx-online-tools. Source for the website providing online SPDX tools
1CloudFail. Python
1threat-intel. Signatures and IoCs from public Volexity blog posts.
1cloud-headers. This is a authoratative listing of all the HTTP headers used by the major cloud providers
1shodan-dorks. How to search on the shodan.io website
1Valid8Proxy. Tool designed for fetching, validating, and storing working proxies.
1buildkite-agent. The Buildkite Agent is an open-source toolkit written in Go for securely running build jobs on any device or network
1canary-packages. Canary packages are software packages that collect telemetry about who is analyzing software registries.
1Bugcrowd-tech. Scraped Bugcrowd programs for techstack
1aMALgamous. Shell and Pen-testing Tool
1direktiv. Serverless Container Orchestration
1hacktricks. Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
1ossec_automation. bash scripts and puppet code to install/uninstall OSSEC
1juicyinfo-nuclei-templates. Nuclei (https://github.com/projectdiscovery/nuclei) templates for extracting juicy info from web pages
1