# BoostSecurity Labs by boostsecurity.io
research
François Proulx
François Proulx VP of Security Research
Alexis-Maurer Fortin
Alexis-Maurer Fortin Senior Product Security Engineer
Sébastien Graveline
Sébastien Graveline Security Researcher
Julien Champoux
Julien Champoux Security Researcher
// alumni
Garance De La Brosse
Garance De La Brosse ex-Junior Security Researcher
Chasen Bettinger
Chasen Bettinger ex-Product Security Engineer
Benoît Côté-Jodoin
Benoît Côté-Jodoin ex-Senior Product Security Engineer
Meet the team →
events
poutine flagship
Build Pipeline Security Scanner
gobelin
Go Repojacking Vulnerability Detector
puant
Unicode PUA Obfuscation Detector
lev-calc
LEV Vulnerability Exploitability Calculator
// coming soon
bagel soon
smokedmeat soon
View all tools →
LOTP
Living Off The Pipeline
Attack Trees
Supply Chain Attack Trees
View all KBs →
ctf about
$ ls -la /usr/local/bin/

Open Source Tools

Security tools and knowledge bases built by the team.

## tools

⭐ poutine

FLAGSHIP scanner

Build Pipeline Security Scanner

Detect misconfigurations and vulnerabilities in your CI/CD pipelines. Scans GitHub Actions, GitLab CI, and other build systems for security issues.

Apache-2.0 View on GitHub

gobelin

RELEASED scanner

Go Repojacking Vulnerability Detector

Scan Go project dependencies for potential repojacking vulnerabilities. Detects missing or deleted GitHub accounts that could be hijacked by attackers.

AGPL-3.0 View on GitHub

puant

RELEASED scanner

Unicode PUA Obfuscation Detector

Tree-sitter-powered detector for malware hidden using Unicode Private Use Area characters. Catches invisible code obfuscation in JavaScript, Python, Go, and Java.

AGPL-3.0 View on GitHub

lev-calc

RELEASED analysis

LEV Vulnerability Exploitability Calculator

Calculate Likely Exploitable Vulnerability scores based on NIST CSWP 41. Predict the probability of vulnerabilities being actively exploited to prioritize patching.

Apache-2.0 View on GitHub

bagel

COMING SOON analysis

Something tasty is baking...

Fresh out of the oven. Almost ready to serve.

GPL-3.0 Coming soon

smokedmeat

COMING SOON offensive

Something spicy is in the smoker...

Our first offensive tool. We're excited about this one.

GPL-3.0 Coming soon
## Knowledge Bases (KBs)

LOTP

Living Off The Pipeline

CI/CD Attack Techniques Knowledge Base

Inventory of how development tools (typically CLIs), commonly used in CI/CD pipelines, have lesser-known RCE-by-design features.

Apache-2.0 Source

Attack Trees

Supply Chain Attack Trees

Deciduous-Generated Threat Models

Visual attack trees for supply chain security threats, generated using the Deciduous tool. Covers source code and build system attack scenarios aligned with SLSA.

CC-BY-SA-4.0 Source
# labs.boostsecurity.io | // supply chain security research by BoostSecurity.io
© 2026 BoostSecurity.io • Built with ❤️ in Montréal, Québec, Canada 🇨🇦
Privacy Policy · Terms of Service
We use cookies for analytics only. Privacy Policy