zizmor
DevSecOps & Pipeline SecurityA static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
The most recently updated tools in our directory.
A static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
Virtual Machine for the Web
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.
A security scanning solution for cloud and containerized environments.
A runtime security and forensics tool for Linux environments leveraging eBPF technology.
A library of attack scenarios and mitigation strategies for Amazon S3, addressing security challenges in the Shared Responsibility Model.
Open Source Cloud Native Application Protection Platform (CNAPP)
A security scanner for Terraform configurations that identifies potential vulnerabilities through static analysis.
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
TerraGoat is a Terraform repository designed to demonstrate common configuration errors in cloud environments.
A CLI tool and Go library for generating Software Bill of Materials (SBOMs) from container images and filesystems.
Simple and flexible tool for managing secrets
Attack Surface Management Platform
Snyk CLI scans and monitors your projects for security vulnerabilities.
AWS Least Privilege for Distributed, High-Velocity Deployment
Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes.
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
Web application firewall (WAF) engine for Apache, IIS and Nginx.