Latest Updates

The most recently updated tools in our directory.

zizmor

zizmor

DevSecOps & Pipeline Security

A static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Velociraptor

Velociraptor

Incident Response & Forensics

A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Trivy

Trivy

Vulnerability Management

A security scanning solution for cloud and containerized environments.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Timesketch

Timesketch

Incident Response & Forensics

Collaborative forensic timeline analysis

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Tracee

Tracee

Incident Response & Forensics

A runtime security and forensics tool for Linux environments leveraging eBPF technology.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
TerraGoat

TerraGoat

DevSecOps & Pipeline Security

TerraGoat is a Terraform repository designed to demonstrate common configuration errors in cloud environments.

Multi-Cloud
Open Source
Self Hosted Only
Teller

Teller

Secrets Management

Cloud native secrets management for developers - never leave your command line for secrets.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Syft

Syft

Supply Chain Security

A CLI tool and Go library for generating Software Bill of Materials (SBOMs) from container images and filesystems.

Multi-Cloud
Open Source
Self Hosted Only
Stratus Red Team

Stratus Red Team

Threat Detection & Response

Granular, Actionable Adversary Emulation for the Cloud

Multi-Cloud
Open Source
Self Hosted Only
Snyk CLI

Snyk CLI

Vulnerability Management

Snyk CLI scans and monitors your projects for security vulnerabilities.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
SOPS

SOPS

Secrets Management

Simple and flexible tool for managing secrets

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Scout Suite

Scout Suite

Security Assessment & Audit

Multi-Cloud Security Auditing Tool

Multi-Cloud
Open Source
Self Hosted + Cloud Options
S3Scanner

S3Scanner

Penetration Testing Tools

Scan for misconfigured S3 buckets across S3-compatible APIs!

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Pacu

Pacu

Penetration Testing Tools

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

AWS
Open Source
Self Hosted Only
Nettacker

Nettacker

Penetration Testing Tools

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Multi-Cloud
Open Source
Self Hosted + Cloud Options
ModSecurity

ModSecurity

Security Monitoring & Logging

Web application firewall (WAF) engine for Apache, IIS and Nginx.

Multi-Cloud
Open Source
Self Hosted Only
MicroBurst

MicroBurst

Penetration Testing Tools

A toolkit for enumerating and exploiting vulnerabilities in Azure cloud environments.

Azure
Open Source
Self Hosted Only
Kubescape

Kubescape

Container & Kubernetes Security

A security platform for Kubernetes that identifies and remediates misconfigurations, vulnerabilities, and compliance issues.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Kubernetes Goat

Kubernetes Goat

Container & Kubernetes Security

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground

Multi-Cloud
Open Source
Self Hosted Only
KubeArmor

KubeArmor

Container & Kubernetes Security

Runtime Security Enforcement System for Kubernetes environments, leveraging Linux Security Modules for workload hardening and policy enforcement.