The pentester's Swiss knife

cloud-native container sandbox

vArmor: A cloud native container sandbox system

vArmor vArmor is a cloud-native container sandbox system. It leverages Linux’s AppArmor LSM, BPF LSM and Seccomp technologies to implement enforcers. It can be used to strengthen container isolation, reduce the kernel attack surface, and increase the difficulty and...

TunnelVision

Mobile Proxies: What They Are and How They Work

Mobile Proxies: What They Are and How They Work Mobile proxies, a gateway to a mobile IP address, are revolutionizing how we experience online privacy and accessibility. Mobile proxies provide an extra layer of...

web-based fuzzer

PinguCrew: Web-Scale Fuzzing for Software Security

PinguCrew PinguCrew is a web-based fuzzer platform that allows security researchers to test their software for vulnerabilities in a scalable and efficient manner. The tool is inspired by the ClusterFuzz tool but aims to remove any...

Azure AD security

BadZure: Exposing Azure AD’s Vulnerable Underbelly

BadZure BadZure is a PowerShell script that leverages the Microsoft Graph SDK to orchestrate the setup of Azure Active Directory tenants, populating them with diverse entities while also introducing common security misconfigurations to create...

Unmasking Malicious .NET Code

Frida-Jit-unPacker: Unmasking Malicious .NET Code

Frida-Jit-unPacker The Frida-Jit-unPacker aims to help researchers and analysts understand the behavior of malicious .NET packed samples in order to provide a mitigation. This tool uses the Frida instrumentation toolkit to inject scripts into the CLR...