{"repo":"boostsecurityio/smokedmeat","free":true,"listed":false,"github":"https://github.com/boostsecurityio/smokedmeat","clone":"git clone https://github.com/boostsecurityio/smokedmeat.git","description":"A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.","language":"Go","stars":374,"topics":["ci","cli","devops","devsecops","exploitation","github-actions","golang","red-team","security","supply-chain"],"license":"AGPL-3.0","category":"deployment-docker-iac","readme_excerpt":"SmokedMeat CI/CD Red Team Framework Like Metasploit, but for CI/CD pipelines. From the makers of the poutine Build Pipeline SAST scanner at BoostSecurity Labs. --- Warning: This tool is for authorized security testing only. SmokedMeat exists because CI/CD pipeline threats are deeply underestimated. Traditional security training rarely covers supply chain attacks, leaving defenders unprepared for techniques that adversaries actively exploit in the wild. We built this to give security teams the ability to learn, practice, and validate defenses against advanced CI/CD attack techniques through realistic red team exercises. Only use against systems you own or have explicit written permission to test. --- What is SmokedMeat? SmokedMeat is a post-exploitation framework for CI/CD pipelines. Point it at a GitHub organization, let it find vulnerable workflows, deploy an implant to a compromised runner, then pivot through cloud providers, extract secrets, and map the blast radius - all from a terminal UI. What it does: 1. Analyze - Scan an org's GitHub Actions workflows for injection vulnerabilities, dangerous triggers, and unsafe checkout patterns (powered by poutine) 2. Exploit - Deploy a stager via PR, issue, comment, or workflow dispatch. When the vulnerable workflow runs, it downloads and executes the implant on the CI runner. 3. Post-exploit - Extract secrets from runner memory, enumerate GitHub token permissions, scan for private keys, and collect loot 4. Pivot - Use captured cre","default_branch":null,"files":null,"tree":[],"storefront":"/r/boostsecurityio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/boostsecurityio/smokedmeat/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}