#1Security integration in CI/CD pipelines, shift-left, and DevOps security automation tools.
Kitploit recommended

Static code analysis tool based on Elasticsearch
Create a VPS on Google Cloud Platform or Digital Ocean easily with Offensive Docker included to launch assessment to the targets.

Application scanning component of purpleteam

CVE-2020-9483 OR CVE-2020-13921

CVE-2016-4468

integration examples for the CVE-2020-25860 fix

TLS checking component of purpleteam

Server scanning component of purpleteam

Stage two containers

Orchestration component of purpleteam

CLI component of purpleteam

threatspec - continuous threat modeling, through code

based on nginx 1.19.5 to fix for CVE-2018-16843, CVE-2018-16844, CVE-2019-9511, CVE-2019-9513, and CVE-2019-9516

Proof-of-concept exploit for CVE-2019-17041, a buffer overflow in rsyslog's parser, demonstrating remote code execution.

This Ansible role provides numerous security-related ssh configurations, providing all-round base protection.

Python script that automatically patches GitHub Actions workflow files to replace deprecated and insecure ::set-env and ::add-path commands with the…

Draw.io libraries for threat modeling diagrams