preflight by SpectralOps

preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.

created at April 29, 2021, 10:37 a.m.

Go

6 +0

149 +0

45 +0

GitHub
harden-runner by step-security

Network egress filtering and runtime security for GitHub-hosted and self-hosted runners

created at Oct. 28, 2021, 4:58 p.m.

TypeScript

7 +0

514 +11

41 +1

GitHub
appsec-education by duo-labs

Presentations, training modules, and other education materials from Duo Security's Application Security team.

created at Oct. 22, 2019, 4:40 p.m.

JavaScript

9 +0

67 +0

14 +0

GitHub
cfngoat by bridgecrewio

Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

created at April 25, 2020, 12:47 a.m.

Unknown languages

10 +0

90 +0

614 +0

GitHub
raindance by devsecops

Project intended to make Attack Maps part of software development by reducing the time it takes to complete them.

created at March 30, 2016, 7:01 a.m.

GCC Machine Description

14 +0

43 +0

22 +0

GitHub
netz by SpectralOps

Discover internet-wide misconfigurations while drinking coffee

created at March 3, 2021, 6:47 p.m.

Go

14 +0

374 +1

46 +0

GitHub
automatic-api-attack-tool by imperva

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

created at Nov. 6, 2019, 7:53 a.m.

Java

15 +0

438 +2

91 +0

GitHub
progpilot by designsecurity

A static analysis tool for security

created at June 20, 2017, 6:04 p.m.

PHP

15 +0

312 +0

63 +0

GitHub
flawfinder by david-a-wheeler

a static analysis tool for finding vulnerabilities in C/C++ source code

created at Nov. 12, 2018, 5:23 p.m.

Python

16 +1

450 +2

81 +2

GitHub
keyscope by SpectralOps

Keyscope is a key and secret workflow (validation, invalidation, etc.) tool built in Rust

created at Oct. 1, 2021, 12:01 p.m.

Rust

17 +0

376 +0

119 +0

GitHub
fulcio by sigstore

Sigstore OIDC PKI

created at Feb. 23, 2021, 3:19 p.m.

Go

17 +0

604 +4

126 +0

GitHub
rekor by sigstore

Software Supply Chain Transparency Log

created at June 17, 2020, 12:04 p.m.

Go

18 +0

834 +4

156 +0

GitHub
scanner-cli by hawkeyesec

A project security/vulnerability/risk scanning tool

created at March 18, 2017, 3:24 p.m.

JavaScript

19 +0

359 +0

89 +0

GitHub
terragoat by bridgecrewio

TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

created at March 27, 2020, 4:56 p.m.

HCL

23 +0

1,102 +1

2,333 +4

GitHub
kube-score by zegl

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your Kubernetes YAML and Charts. Static code analysis for Kubernetes.

created at Sept. 16, 2018, 1:19 p.m.

Go

23 +1

2,588 +1

174 +1

GitHub
kics by Checkmarx

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

created at July 8, 2020, 9:46 p.m.

Open Policy Agent

25 +0

1,902 +4

286 +0

GitHub
kubectl-kubesec by controlplaneio

Security risk analysis for Kubernetes resources

created at May 8, 2018, 8:52 a.m.

Go

25 +0

500 +0

37 +0

GitHub
teller by tellerops

Cloud native secrets management for developers - never leave your command line for secrets.

created at March 24, 2021, 10:49 a.m.

Go

26 +0

2,551 +10

164 +0

GitHub
conftest by open-policy-agent

Write tests against structured configuration data using the Open Policy Agent Rego query language

created at March 28, 2019, 5:12 p.m.

Go

27 +0

2,790 +2

296 +0

GitHub
regula by fugue

Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google Cloud, and Kubernetes security and compliance using Open Policy Agent/Rego

created at Dec. 17, 2019, 2:27 p.m.

Open Policy Agent

30 +0

934 +3

105 -1

GitHub