zizmor
DevSecOps & Pipeline SecurityA static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
The most recently updated tools in our directory.
A static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.
A security scanning solution for cloud and containerized environments.
Collaborative forensic timeline analysis
A runtime security and forensics tool for Linux environments leveraging eBPF technology.
TerraGoat is a Terraform repository designed to demonstrate common configuration errors in cloud environments.
Cloud native secrets management for developers - never leave your command line for secrets.
A CLI tool and Go library for generating Software Bill of Materials (SBOMs) from container images and filesystems.
Granular, Actionable Adversary Emulation for the Cloud
Snyk CLI scans and monitors your projects for security vulnerabilities.
Simple and flexible tool for managing secrets
Multi-Cloud Security Auditing Tool
Scan for misconfigured S3 buckets across S3-compatible APIs!
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
Web application firewall (WAF) engine for Apache, IIS and Nginx.
A toolkit for enumerating and exploiting vulnerabilities in Azure cloud environments.
A security platform for Kubernetes that identifies and remediates misconfigurations, vulnerabilities, and compliance issues.
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground
Runtime Security Enforcement System for Kubernetes environments, leveraging Linux Security Modules for workload hardening and policy enforcement.