Latest Updates

The most recently updated tools in our directory.

zizmor

zizmor

DevSecOps & Pipeline Security

A static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
WebVM

WebVM

Infrastructure Security & Hardening

Virtual Machine for the Web

Multi-Cloud
Open Source
Self Hosted Only
Vuls

Vuls

Vulnerability Management

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Velociraptor

Velociraptor

Incident Response & Forensics

A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Trivy

Trivy

Vulnerability Management

A security scanning solution for cloud and containerized environments.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
tfsec

tfsec

DevSecOps & Pipeline Security

A security scanner for Terraform configurations that identifies potential vulnerabilities through static analysis.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Syft

Syft

Supply Chain Security

A CLI tool and Go library for generating Software Bill of Materials (SBOMs) from container images and filesystems.

Multi-Cloud
Open Source
Self Hosted Only
Snyk CLI

Snyk CLI

Vulnerability Management

Snyk CLI scans and monitors your projects for security vulnerabilities.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
SOPS

SOPS

Secrets Management

Simple and flexible tool for managing secrets

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Sn1per

Sn1per

Penetration Testing Tools

Attack Surface Management Platform

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Security Monkey

Security Monkey

Archived
Security Monitoring & Logging

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

Multi-Cloud
Open Source
Self Hosted Only
S3Scanner

S3Scanner

Penetration Testing Tools

Scan for misconfigured S3 buckets across S3-compatible APIs!

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Rekor

Rekor

Supply Chain Security

Software Supply Chain Transparency Log

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Prowler

Prowler

Security Assessment & Audit

Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
OWASP WrongSecrets CTF Party

OWASP WrongSecrets CTF Party

Security Training & Simulation

Run Capture the Flags and Security Trainings with OWASP WrongSecrets

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Nettacker

Nettacker

Penetration Testing Tools

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Kubescape

Kubescape

Container & Kubernetes Security

A security platform for Kubernetes that identifies and remediates misconfigurations, vulnerabilities, and compliance issues.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
kube-bench

kube-bench

Container & Kubernetes Security

A tool to ensure Kubernetes deployments adhere to industry-standard security best practices as outlined in the CIS Kubernetes Benchmark.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Koku

Koku

Cost Security & FinOps

An open source solution for cost management of cloud and hybrid cloud environments.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Interactsh

Interactsh

Penetration Testing Tools

An OOB interaction gathering server and client library