<b/s>
$ecur1ty H4ckath0n.By Sola

You could win $20,000 building something that makes security less annoying.

Build agentic solutions that tackle real, boring security tasks with Sola Security. Submissions are open for three weeks, and the internet chooses the winners.

Prize pool.

$35,000

Hackthon ended

June 30, 2026

Winners announced

July 2, 2026

Submissions

Access Review Prioritizer1st place

Access Review Prioritizer

1752

#yaffavasserman

AI prioritizes high-risk access review findings, helping managers focus on the accounts that require immediate attention.

GitHub
CSV
FirstWatch2nd place

FirstWatch

1347

#Mai Barneis

Monitors new hires first 90 days across Okta, GitHub & AWS — scores risk, explains why, and auto-remediates real threats.

AWS
Okta
GitHub
SignalOps Nexus: GitHub Risk-to-Remediation Router3rd place

SignalOps Nexus: GitHub Risk-to-Remediation Router

1023

#Shobhit

Turns risky GitHub repo signals into owner-assigned remediation packages with mock Slack/Jira routing, verification, and audit evidence.

GitHub
Obius

Obius

362

#Kenji

AI-powered cyber risk intelligence that turns Sola evidence into attack narratives, blast-radius graphs, and trusted remediation.

GitHub
GCP
Jira (connector)
Privilege Esclation Hunter

Privilege Esclation Hunter

317

#יובל גינת

Security teams know who their administrators are, but often miss users who can become administrators through indirect privilege escalation paths.

Azure
Google Sheets
Falcon Remediation Autopilot

Falcon Remediation Autopilot

205

#Shavit Malovani

Falcon Remediation Autopilot turns CrowdStrike alert overload into ranked, explainable remediation plans that route the next SOC action.

CrowdStrike
Jira (connector)
Slack (connector)
SaaS OAuth Risk Scorer

SaaS OAuth Risk Scorer

178

#aryansakaria

Scores every Google Workspace OAuth grant by risk — permissions × vendor trust + exposure - with live Sola queries, typosquat detection, and Slack alerts.

GCP
Google Workspace
Slack (connector)
AttackCoverage

AttackCoverage

149

#Matt

You can't defend what you can't see. AttackCoverage maps every MITRE ATT&CK technique against your real detection rules exposing the gaps an attacker would f

CrowdStrike
CSV
Pangolin

Pangolin

100

#Huang Chung YI

CI/CD security scanner: Sola MCP data + regex patterns + LLM attack chain analysis + Semgrep cross-validation + auto-fix PR generation.

GitHub
Semgrep
Slack (connector)
CSV
Gitector

Gitector

63

#Aryan Jain

A super simple way to get GitHub detection for weak security, with slack alerts

GitHub
Cross-Stack "Toxic Combination" & Shadow AI Reference Architecture

Cross-Stack "Toxic Combination" & Shadow AI Reference Architecture

60

#mataninio

A 5-block cross-stack detection blueprint correlating compromised endpoints (CrowdStrike) with privileged identity and risky Shadow AI OAuth grants.

CrowdStrike
Frictionless Developer Off-Boarder

Frictionless Developer Off-Boarder

45

#noobcoder

The one-stop, worry-less solution for every company.

GitHub
Okta
EdgeProof

EdgeProof

44

#N DIVIJ

Maps public Cloudflare/Web Checker assets to GitHub repos and weak deployment controls to expose real code-to-edge breach paths.

GitHub
Cloudflare
Identity hygiene for cloud IAM inactivity

Identity hygiene for cloud IAM inactivity

20

#Fabio R.

I got tired of exporting CSVs to find dormant accounts. This app scans AWS, Azure and GCP, sends weekly digests and tickets + 2 canvases for my CISO and team.

AWS
Azure
GCP
Ash's Unencrypted AWS Asset Hunter

Ash's Unencrypted AWS Asset Hunter

18

#Ash9100

My project finds S3 buckets, EBS volumes and dbs that were created without encryption enabled

AWS
ProofMode

ProofMode

17

#Jawahar

Live audit evidence packets from Sola, GitHub, and AWS.

AWS
GitHub
Breachscope

Breachscope

16

#Michelle

BreachScope reveals the real blast radius of a compromised AWS identity in seconds.

AWS
GitHub
CSV
Google Sheets
Intent Archeologist

Intent Archeologist

13

#Isaac

Every enterprise cloud is haunted by the ghosts of engineers who left the company years ago

GitHub
Automated Scheduled Access Review

Automated Scheduled Access Review

12

#Ben J. D.

AI agent that audits identity access across 7 platforms, flags risks, and generates an HTML report.

AWS
Azure
GCP
Okta
Google Workspace
GitHub
HiBob
VibeAudit

VibeAudit

11

#debabratapattnayak24

One-click pre-launch security scorecard for apps built with Lovable, Bolt, Cursor, v0, and Replit. Five audit layers. Powered by Sola's security

AWS
GCP
SentinelOne
GitHub
OpenAI
Cloudflare
CSV
Sentinel Data Lake
ScopeShield

ScopeShield

10

#Blue

Audits GitHub App installations, scores risky permissions, and creates remediation steps, mock routing, and audit evidence.

GitHub
Website Threat Surface Monitor

Website Threat Surface Monitor

8

#Pitani Ganesh

Automated attack surface management platform that discovers exposures, tracks security trends, and generates AI-powered remediation recommendations.

GitHub
Cloudflare
WordPress