#1Tools for auditing configurations, permissions, and services in cloud platforms (IaaS, PaaS).
Kitploit recommended

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…
A powerful testing tool for Kubernetes clusters.

Attack Surface Management since before Attack Surface Management was a thing

A tool for quickly evaluating IAM permissions in AWS.

Security risk analysis for Kubernetes resources

A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC

Curated timeline of AWS S3 bucket misconfigurations, exposed data, and leaked IAM credentials, with incident links for cloud security defenders and…

Audits Azure AD and Exchange Online configurations for hard-to-find permissions, federation trusts, mail forwarding rules, and delegated access to…

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

AWS Least Privilege for Distributed, High-Velocity Deployment

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

Getting a handle on container security

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

AWS Auditing & Hardening Tool

a Damn Vulnerable Serverless Application

Official Elastic Skills

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…