Latest Updates

The most recently updated tools in our directory.

sftp-gcs

sftp-gcs

Data Security & Encryption

A bridge between SFTP and Google Cloud Storage (GCS) that allows users to access GCS buckets via SFTP and sync files between them.

GCP
Open Source
Cloud Native Service
SansShell

SansShell

Identity & Access Management

A non-interactive daemon for host management using gRPC for remote interactions and policy enforcement through Open Policy Agent (OPA).

Multi-Cloud
Open Source
Self Hosted Only
zizmor

zizmor

DevSecOps & Pipeline Security

A static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Jenganizer

Jenganizer

Security Assessment & Audit

Jenganizer is a tool designed to help cloud security teams gain visibility into hidden services within AWS by tracking events triggered by user actions.

AWS
Open Source
Self Hosted Only
AWS Security Incident Response

AWS Security Incident Response

Incident Response & Forensics

AWS Security Incident Response automates the monitoring and investigation of security findings, streamlining communication and coordination for security management.

AWS
Proprietary
Cloud Native Service
Falco

Falco

Container & Kubernetes Security

Falco is a cloud native runtime security tool for Linux that detects and alerts on abnormal behavior and potential security threats in real-time by monitoring system calls and kernel events.

Multi-Cloud
Open Source
Self Hosted Only
shell-exec-cloud-run

shell-exec-cloud-run

Container & Kubernetes Security

Execute a shell command within Cloud Run

GCP
Open Source
Cloud Native Service
Terraform Provider for Remote Code Execution

Terraform Provider for Remote Code Execution

Configuration & Change Management

This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file. It highlights the risks associated with Terraform state files.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
vpcshark

vpcshark

Network Security

An open source Wireshark extcap to make ad hoc mirroring of AWS EC2 traffic easier

AWS
Open Source
Self Hosted Only
Conditional Access Management Tools

Conditional Access Management Tools

Identity & Access Management

A set of Conditional Access (CA) policies and PowerShell management tools for Microsoft Entra ID, designed to enhance security while maintaining usability.

Azure
Open Source
Self Hosted Only
iam-simulate

iam-simulate

Identity & Access Management

An IAM Simulator that outputs detailed explanations of how a request was evaluated.

AWS
Open Source
Self Hosted Only
aws-break-glass-role

aws-break-glass-role

Identity & Access Management

Create a break glass role for emergency use in AWS to limit access and configure alerts and logging for secure usage.

AWS
Open Source
Self Hosted Only
breakglass

breakglass

Identity & Access Management

emergency/debugging access for gokrazy installations

Multi-Cloud
Open Source
Self Hosted Only
NAXSI

NAXSI

Threat Detection & Response

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

Multi-Cloud
Open Source
Self Hosted Only
Dependabot

Dependabot

Vulnerability Management

Dependabot automates dependency updates in software projects by integrating with GitHub to monitor manifests and generate pull requests for updates.

Multi-Cloud
Proprietary
Cloud Native Service
Timesketch

Timesketch

Incident Response & Forensics

Collaborative forensic timeline analysis

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Kube-hunter

Kube-hunter

Penetration Testing Tools

A security tool for identifying and exploiting vulnerabilities in Kubernetes clusters.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Snyk Container

Snyk Container

Container & Kubernetes Security

A tool for identifying and remediating vulnerabilities in containerized applications.

Multi-Cloud
Open Source + Commercial
Cloud Service Only
cwe-monitor-secgrp

cwe-monitor-secgrp

Security Monitoring & Logging

This CloudWatch Events rule Lambda function evaluates AWS API calls that change Amazon EC2 security group ingress rules. The function flags rules that violate a preconfigured policy.

AWS
Open Source
Cloud Service Only
CloudSecurity

CloudSecurity

Secrets Management

Cloud security projects with Spring Cloud Config Server and Vault