Skip to content
View loresuso's full-sized avatar
  • Sysdig
  • Madrid

Organizations

@falcosecurity

Block or report loresuso

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Falco container plugin

C++ 6 Updated Dec 20, 2024

ultralytics-clone for analyzing Ultralytics GitHub Actions exploit with Harden-Runner

Python 1 3 Updated Dec 30, 2024

#supply #chain #attack #detection

YARA 481 36 Updated Jan 6, 2025

This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.

Go 48 2 Updated Dec 8, 2024

OpenSSF Scorecard - Security health metrics for Open Source

Go 4,701 510 Updated Jan 2, 2025

A container runtime written in Rust

Rust 6,407 353 Updated Jan 6, 2025

Community curated list of templates for the nuclei engine to find security vulnerabilities.

JavaScript 9,530 2,687 Updated Jan 6, 2025

Testcontainers for Go is a Go package that makes it simple to create and clean up container-based dependencies for automated integration/smoke tests. The clean, easy-to-use API enables developers t…

Go 3,761 510 Updated Jan 2, 2025

GitHub Actions Pipeline Enumeration and Attack Tool

Python 577 53 Updated Aug 13, 2024

GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.

Python 225 23 Updated Jan 3, 2025

Proof-of-concept code for research into GitHub Actions Cache poisoning.

Python 21 7 Updated Dec 12, 2024

GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

JavaScript 450 259 Updated Dec 19, 2024

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

Shell 494 52 Updated Jan 3, 2025

ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server

Shell 1,418 166 Updated Dec 31, 2024

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …

Go 21,266 2,557 Updated Jan 2, 2025

⚙ DevSecOps Kubernetes Playground ("A Hacker's Guide to Kubernetes")

Shell 16 2 Updated Sep 29, 2023

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

C 3,468 417 Updated Dec 27, 2024

The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

Shell 9,220 1,022 Updated Oct 21, 2024

An encyclopedia for offensive and defensive security knowledge in cloud native technologies.

Dockerfile 1,784 219 Updated Jan 3, 2025

Welcome to the Meta Threat Research Indicator Repository, a dedicated resource for the sharing of Indicators of Compromise (IOCs) and other threat indicators with the external research community

Python 156 18 Updated Dec 3, 2024

Terratest is a Go library that makes it easier to write automated tests for your infrastructure code.

Go 7,554 1,334 Updated Jan 1, 2025

macOS system monitor in your menu bar

Swift 27,077 896 Updated Jan 5, 2025

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

C 7,071 1,102 Updated Dec 16, 2024

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.

PowerShell 2,200 324 Updated Dec 31, 2024

PoC and Detection for CVE-2024-21626

71 11 Updated Feb 6, 2024

Azure Workload Identity full deployment with Terraform.

HCL 9 6 Updated Dec 5, 2022

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

Go 11,355 2,033 Updated Aug 21, 2024

Azure Data Exporter for BloodHound

Go 589 82 Updated Dec 18, 2024
Next