Latest Updates

The most recently updated tools in our directory.

zizmor

zizmor

DevSecOps & Pipeline Security

A static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
WebVM

WebVM

Infrastructure Security & Hardening

Virtual Machine for the Web

Multi-Cloud
Open Source
Self Hosted Only
Vuls

Vuls

Vulnerability Management

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Velociraptor

Velociraptor

Incident Response & Forensics

A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Trivy

Trivy

Vulnerability Management

A security scanning solution for cloud and containerized environments.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Tracee

Tracee

Incident Response & Forensics

A runtime security and forensics tool for Linux environments leveraging eBPF technology.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
ThreatModel for Amazon S3

ThreatModel for Amazon S3

Threat Detection & Response

A library of attack scenarios and mitigation strategies for Amazon S3, addressing security challenges in the Shared Responsibility Model.

AWS
Open Source
Self Hosted Only
ThreatMapper

ThreatMapper

Threat Detection & Response

Open Source Cloud Native Application Protection Platform (CNAPP)

Multi-Cloud
Open Source
Self Hosted + Cloud Options
tfsec

tfsec

DevSecOps & Pipeline Security

A security scanner for Terraform configurations that identifies potential vulnerabilities through static analysis.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Terrascan

Terrascan

Archived
DevSecOps & Pipeline Security

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
TerraGoat

TerraGoat

DevSecOps & Pipeline Security

TerraGoat is a Terraform repository designed to demonstrate common configuration errors in cloud environments.

Multi-Cloud
Open Source
Self Hosted Only
Syft

Syft

Supply Chain Security

A CLI tool and Go library for generating Software Bill of Materials (SBOMs) from container images and filesystems.

Multi-Cloud
Open Source
Self Hosted Only
SOPS

SOPS

Secrets Management

Simple and flexible tool for managing secrets

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Sn1per

Sn1per

Penetration Testing Tools

Attack Surface Management Platform

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Snyk CLI

Snyk CLI

Vulnerability Management

Snyk CLI scans and monitors your projects for security vulnerabilities.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Repokid

Repokid

Identity & Access Management

AWS Least Privilege for Distributed, High-Velocity Deployment

AWS
Open Source
Self Hosted Only
Prowler

Prowler

Security Assessment & Audit

Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Pacu

Pacu

Penetration Testing Tools

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

AWS
Open Source
Self Hosted Only
Nettacker

Nettacker

Penetration Testing Tools

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Multi-Cloud
Open Source
Self Hosted + Cloud Options
ModSecurity

ModSecurity

Security Monitoring & Logging

Web application firewall (WAF) engine for Apache, IIS and Nginx.