A simple, secure, easy-to-use bastion and session auditing system. Supports RDP, SSH, VNC, Telnet, HTTP, records and replays sessions for auditing and compliance.
-
Updated
Sep 13, 2026 - TypeScript
A simple, secure, easy-to-use bastion and session auditing system. Supports RDP, SSH, VNC, Telnet, HTTP, records and replays sessions for auditing and compliance.
An enhanced fork of Shizuku — adds Root/ADB/Dhizuku unification, a Plus API suite, and OneUI/Android 16+ compatibility fixes, while staying fully compatible with existing Shizuku apps.
Lightweight, self-hosted Entra ID governance portal: track app/identity ownership, surface credential and access risk, and score tenant health — running in your own Azure subscription.
Omni-SAG — auditable Linux privileged-access gateway (SSH + SFTP): AD+MFA, single-dialer authz, tamper-evident evidence chain, recording, ICAP inspection, CyberArk injection, four-eyes approvals, control-plane API/TUI. Go modular monolith.
Transforms IAM exports into a human-readable identity risk narrative with executive summaries and engineer-focused findings.
Deploy, audit and maintain an Active Directory tier model from a single PowerShell script and one JSON file. Idempotent, plans before it writes.
Self-hosted open-source credential manager for teams. Share company accounts without exposing passwords. Chrome extension auto-login. One-click offboarding.
PowerShell-first Active Directory security posture auditor for privileged access, Kerberos, Windows LAPS, Group Policy, ACLs, and offline drift analysis.
local proof-of-concept implementing the Sovereign Intent Framework - a runtime governance architecture for agentic AI. Tests deterministic policy enforcement, intent manifest hashing, and audit trail generation against seeded adversarial scenarios.
Saviynt connector starter for importing Okta users, admin roles, permissions, and privileged access relationships into an identity governance workflow.
CyberArk session-risk console for privilege drift, checkout posture, high-risk access paths, and evidence-ready remediation routing.
Synthetic database activity monitoring and SQL threat detection portfolio covering privileged DBA activity, sensitive table access, suspicious query patterns, alert triage, dashboards, and control mapping.
Pre-execution security for human and AI-generated commands. Correlates intent, privilege, behavior, blast radius, project state, and AV/EDR/SIEM signals to ALLOW, REVIEW, or BLOCK.
Detects changes to identity and access posture. Diffs your directory against a baseline, so it reports what moved rather than everything that is imperfect.
Privileged-access detections for Microsoft Sentinel (KQL, ATT&CK-mapped)
Finds privileged Azure RBAC and Entra role assignments that posture tools miss
CyberArk/Idira PAM lifecycle automation with psPAS (PowerShell)
Enterprise banking IAM architecture implementing tiered Active Directory administration, RBAC, PowerShell provisioning, Group Policy security controls, and independent security assurance.
Azure landing-zone privileged-access guardrails via Azure Policy + Verified Modules
To associate your repository with the privileged-access topic, visit your repo's landing page and select "manage topics."