zizmor
DevSecOps & Pipeline SecurityA static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
The most recently updated tools in our directory.
A static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
Virtual Machine for the Web
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.
A security scanning solution for cloud and containerized environments.
Collaborative forensic timeline analysis
Cloud native secrets management for developers - never leave your command line for secrets.
A CLI tool and Go library for generating Software Bill of Materials (SBOMs) from container images and filesystems.
Granular, Actionable Adversary Emulation for the Cloud
Simple and flexible tool for managing secrets
Attack Surface Management Platform
Snyk CLI scans and monitors your projects for security vulnerabilities.
Multi-Cloud Security Auditing Tool
Software Supply Chain Transparency Log
Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes.
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX
ManageIQ Open-Source Management Platform
A security platform for Kubernetes that identifies and remediates misconfigurations, vulnerabilities, and compliance issues.