zizmor
DevSecOps & Pipeline SecurityA static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
The most recently updated tools in our directory.
A static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
Virtual Machine for the Web
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.
A security scanning solution for cloud and containerized environments.
A security scanner for Terraform configurations that identifies potential vulnerabilities through static analysis.
A CLI tool and Go library for generating Software Bill of Materials (SBOMs) from container images and filesystems.
Snyk CLI scans and monitors your projects for security vulnerabilities.
Simple and flexible tool for managing secrets
Attack Surface Management Platform
Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.
Scan for misconfigured S3 buckets across S3-compatible APIs!
Software Supply Chain Transparency Log
Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes.
Run Capture the Flags and Security Trainings with OWASP WrongSecrets
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
A security platform for Kubernetes that identifies and remediates misconfigurations, vulnerabilities, and compliance issues.
A tool to ensure Kubernetes deployments adhere to industry-standard security best practices as outlined in the CIS Kubernetes Benchmark.
An open source solution for cost management of cloud and hybrid cloud environments.
An OOB interaction gathering server and client library