Skip to content
View medelibero's full-sized avatar

Block or report medelibero

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
77 stars written in Python
Clear filter

Example solutions demonstrating how to implement patterns within the AWS Security Reference Architecture guide using CloudFormation (including Customizations for AWS Control Tower) and Terraform.

Python 1,104 291 Updated Jun 23, 2025

NGINX configuration static analyzer

Python 1,097 26 Updated Oct 25, 2025

The Correlated CVE Vulnerability And Threat Intelligence Database API

Python 944 242 Updated May 28, 2021

Collection of Proof of Concepts and Potential Targets for #ShellShocker

Python 890 191 Updated May 16, 2020

Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.

Python 728 74 Updated Sep 20, 2025

GitHub Actions Pipeline Enumeration and Attack Tool

Python 712 64 Updated Sep 17, 2025

graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.

Python 692 81 Updated Jun 9, 2025

A collection of fuzzers in a harness for testing the SpiderMonkey JavaScript engine.

Python 638 112 Updated Feb 10, 2023

Protection against Model Serialization Attacks

Python 599 123 Updated Oct 20, 2025
Python 573 66 Updated Dec 7, 2022

Security Auditor Utility for GraphQL APIs

Python 542 76 Updated Nov 7, 2025

Simple Python library/structure to ablate features in LLMs which are supported by TransformerLens

Python 521 71 Updated Jun 11, 2024

ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.

Python 509 69 Updated Oct 7, 2025

Machine learning driven web application firewall to detect malicious queries with high accuracy.

Python 431 127 Updated May 15, 2017

Automated web vulnerability scanning with LLM agents

Python 362 44 Updated Jun 18, 2025

A command line tool that validates AWS IAM Policies in a Terraform template against AWS IAM best practices

Python 343 30 Updated Jun 9, 2025

GraphQL automated security testing toolkit

Python 329 23 Updated Feb 20, 2024

Offensive DNS server

Python 323 160 Updated Jan 18, 2022

Halberd : Multi-Cloud Agentic Attack Tool

Python 320 33 Updated Sep 1, 2025

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab.

Python 313 15 Updated Oct 8, 2025

CVE-2025-49844 (RediShell)

Python 299 60 Updated Oct 7, 2025

Auto Domain Admin and Network Exploitation.

Python 299 68 Updated Dec 21, 2017

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Python 280 14 Updated Sep 11, 2025

Python API security testing tool from OpenStack Security Group

Python 275 79 Updated May 13, 2020

Python implementation of GhostPack's Seatbelt situational awareness tool

Python 265 22 Updated Nov 12, 2024

Unauthenticated enumeration of AWS, Azure, and GCP Principals

Python 249 33 Updated Nov 13, 2024

Dropbox LLM Security research code and results

Python 241 31 Updated May 21, 2024
Python 234 29 Updated Jan 14, 2024

A tool to surface security issues in python code

Python 226 24 Updated Apr 20, 2017