Lightweight, self-hosted Entra ID governance portal: track app/identity ownership, surface credential and access risk, and score tenant health — running in your own Azure subscription.
-
Updated
Jul 3, 2026 - PowerShell
Lightweight, self-hosted Entra ID governance portal: track app/identity ownership, surface credential and access risk, and score tenant health — running in your own Azure subscription.
10 hands-on Microsoft Cybersecurity Architect SC-100 labs covering Zero Trust, MCRA, MCSB, ransomware resilience, SIEM, XDR, SOAR, Entra ID, privileged access, Purview, Defender for Cloud, Azure Policy, hybrid and multicloud posture, infrastructure, application, data, AI, and Microsoft 365 security architecture.
Transforms IAM exports into a human-readable identity risk narrative with executive summaries and engineer-focused findings.
Self-hosted open-source credential manager for teams. Share company accounts without exposing passwords. Chrome extension auto-login. One-click offboarding.
Deploy, audit and maintain an Active Directory tier model from a single PowerShell script and one JSON file. Idempotent, plans before it writes.
PowerShell-first Active Directory security posture auditor for privileged access, Kerberos, Windows LAPS, Group Policy, ACLs, and offline drift analysis.
Detects changes to identity and access posture. Diffs your directory against a baseline, so it reports what moved rather than everything that is imperfect.
CyberArk/Idira PAM lifecycle automation with psPAS (PowerShell)
Synthetic database activity monitoring and SQL threat detection portfolio covering privileged DBA activity, sensitive table access, suspicious query patterns, alert triage, dashboards, and control mapping.
CyberArk session-risk console for privilege drift, checkout posture, high-risk access paths, and evidence-ready remediation routing.
Pre-execution security for human and AI-generated commands. Correlates intent, privilege, behavior, blast radius, project state, and AV/EDR/SIEM signals to ALLOW, REVIEW, or BLOCK.
local proof-of-concept implementing the Sovereign Intent Framework - a runtime governance architecture for agentic AI. Tests deterministic policy enforcement, intent manifest hashing, and audit trail generation against seeded adversarial scenarios.
Saviynt connector starter for importing Okta users, admin roles, permissions, and privileged access relationships into an identity governance workflow.
IAM least-privilege & break-glass broker roles, verified with Access Analyzer + Checkov
Privileged-access detections for Microsoft Sentinel (KQL, ATT&CK-mapped)
Azure landing-zone privileged-access guardrails via Azure Policy + Verified Modules
Omni-SAG — auditable Linux privileged-access gateway (SSH + SFTP): AD+MFA, single-dialer authz, tamper-evident evidence chain, recording, ICAP inspection, CyberArk injection, four-eyes approvals, control-plane API/TUI. Go modular monolith.
Enterprise PAM demonstration - HashiCorp Vault + Delinea Secret Server with cross-platform automation, migration tooling, and architecture comparison
Network dependent Sudo session logger and logplayback GUI
Add a description, image, and links to the privileged-access topic page so that developers can more easily learn about it.
To associate your repository with the privileged-access topic, visit your repo's landing page and select "manage topics."