30 open-source projects similar to accenture/jenkins-attack-framework, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Jenkins Attack Framework alternative.
Gato-X is a FAST scanning and attack tool for GitHub Actions pipelines. You can use it to identify Pwn Requests, Actions Injection, TOCTOU Vulnerabilities, and Self-Hosted Runner takeover at scale using just a single API token. It will also analyze cross-repository workflows and reusable…
NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.
An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻
PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. This is possible via other protocols as well.
The largest open-source database for detecting secrets, API keys, passwords, tokens, and more. Use secrets-patterns-db to feed your secret scanning engine with regex patterns for identifying secrets.
GitFive is an OSINT tool to investigate GitHub profiles.
Redis(<=5.0.5) RCE
BaRMIe is a tool for enumerating and attacking Java RMI (Remote Method Invocation) services.
Automatic SSRF fuzzer and exploitation tool
Nord Stream is a tool that allows you extract secrets stored inside CI/CD environments by deploying malicious pipelines.
Nosql-Exploitation-Framework