zizmor
DevSecOps & Pipeline SecurityA static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
The most recently updated tools in our directory.
A static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
Virtual Machine for the Web
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.
A security scanning solution for cloud and containerized environments.
Collaborative forensic timeline analysis
Open Source Cloud Native Application Protection Platform (CNAPP)
A scalable, open-source security incident response platform that integrates case management, task assignment, and collaboration tools.
A security scanner for Terraform configurations that identifies potential vulnerabilities through static analysis.
TerraGoat is a Terraform repository designed to demonstrate common configuration errors in cloud environments.
This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file. It highlights the risks associated with Terraform state files.
A CLI tool and Go library for generating Software Bill of Materials (SBOMs) from container images and filesystems.
Granular, Actionable Adversary Emulation for the Cloud
Simple and flexible tool for managing secrets
Attack Surface Management Platform
Snyk CLI scans and monitors your projects for security vulnerabilities.
Multi-Cloud Security Auditing Tool
Scan for misconfigured S3 buckets across S3-compatible APIs!
A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure
Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes.