Detect drift. Defend cloud.
-
Updated
Feb 21, 2026 - Go
Detect drift. Defend cloud.
Encrypted vault, ZK settlement archiving, x402 payment receipts, Agent Passport binding, and Solana anchoring for OpenClaw and agent runtimes. Drop-in stack — compression, privacy, payments, identity.
AI-powered multi-chain Web3 security toolkit. Scan smart contracts across 6 EVM chains in minutes, not weeks.
Security Notes/Tools/Scripts
Deterministic, local-first context builder for flow automation exports: redacts sensitive data, detects risks, and produces auditable bundles for AI assistants and support workflows: flow analysis, subflow expansion, secret redaction, token budgeting, and reproducible bundle generation via CLI and VUE web app.
Local-first context-integrity engine. Reconstructs trust from immutable runtime history, contains risky actions in QTF, and gates promotion through EXT.
SQL Server security audit tool that scans .NET/web configs for SQL connection strings and secrets and reports risky features like xp_cmdshell and password reuse.
Automated reconnaissance and attack-surface analysis pipeline for infrastructure visibility, asset discovery, and vulnerability identification.
High‐performance iocx plugin for detecting Windows Registry keys, values, and persistence locations. Includes full test coverage, performance benchmarks, and security checks.
Umbrella CLI for the NuClide Visor tool family. Catches stale or missing tool binaries before a survey starts.
Educational C2 Framework for Red Team Learning
Deterministic Python CLI for repository hygiene checks and pre-commit secret scanning.
Rev-AI is an advanced reverse shell implementation that leverages AI (DeepSeek API) to generate Linux commands based on natural language queries. It provides a secure communication channel between a target system and a command server with automatic reconnection capabilities.
Cross-platform persistence detection CLI with baseline/diff analysis for Linux and Windows.
CI scanner for RAG corpus risks: prompt injection, risky HTML/Markdown, PII, and secret-like content.
Access Log Correlator - Python based access log correlation tool for detecting failed login bursts with schema validation and JSON output.
Validate Infrastructure as Code against CMMC Level 2 and NIST 800-171 security controls
ProtoAudit is a research-grade toolkit for protocol behavior analysis, cryptographic metadata inspection, and randomness anomaly detection. It helps to identify protocol misuse patterns such as challenge reuse, retry loops, deterministic randomness, and handshake inconsistencies. Designed for protocol research, security analysis, and CTF tasks.
Terminal flight recorder for CTFs and authorized pentests with structured reporting.
HacxGPT CLI — Open-source command-line interface for unrestricted AI model access with multi-provider support, prompt injection research capabilities, configurable API endpoints, Termux/Linux/Windows compatibility, and Rich terminal UI for security research and red-team evaluation
Add a description, image, and links to the security-tooling topic page so that developers can more easily learn about it.
To associate your repository with the security-tooling topic, visit your repo's landing page and select "manage topics."