Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
awesome-devsecops — An authoritative list of awesome devsecops tools with the help from community experiments and contributions. | Kitploit
Tools/GitHubGitHub/devsecops/awesome-devsecops
Vulnerability ScannersPenetration TestingDevSecOpsSecret DetectionThreat IntelligenceLearning & EducationRed TeamingCurated ResourcesLearning Paths & CoursesLabs & Practice
GitHubdevsecops/awesome-devsecops
5.5k1.2k334 years agoReviewed by Kitploit

awesome-devsecops

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Awesome DevSecOps Awesome

Inspired by the awesome-* trend on GitHub. This is a collection of documents, presentations, videos, training materials, tools, services and general leadership that support the DevSecOps mission. These are the essential building blocks and tidbits that can help you to arrange for a DevSecOps experiment or to help you build out your own DevSecOps program.

This list will not be fully comprehensive and will change as DevSecOps matures. We intend for it to be an awesome list that grows and changes as the community learns and improves how DevSecOps is implemented and adopted. To be included in this list, the information, tools, vendors or initiative must provide for Free or Open Source capabilities that help with the DevSecOps mission. Links that lead to a commercial aspect are noted with a (P).

Table of Contents generated with DocToc

  • Information
    • Guidelines
    • Presentations
    • Initiatives
    • Keeping Informed
    • Wardley Maps for Security
  • Training
    • Labs
    • Vulnerable Test Targets
    • Conferences
    • Podcasts
    • Books
  • Tools
    • Dashboards
    • Automation
    • Hunting
    • Testing
    • Alerting
    • Threat Intelligence
    • Attack Modeling
    • Secret Management
    • Red Team
    • Visualization
    • Sharing
    • ChatOps

Information

We've been working across the industry to learn more about the different types of DevOps + Security initiatives. This collection has been pulled together and includes: Podcasts, Videos, Presentations, and other Media to help you learn more about DevSecOps, SecDevOps, DevOpsSec, and/or DevOps + Security.

Guidelines

While we're not into the paper-way of doing things, sharing sound advice and good recommendations can make software stronger. We aim to make these guidelines better through code.

  • Introduction to DevSecOps - DZone Refcard
  • Security Champions Playbook
  • Security Guide for Web Developers
  • A practical guide to build DAST with OWASP Zap
  • Introduction to security testing and tools
  • DevSecOps Hub

Presentations

Many talks are now targeting the change of adding Security into the DevOps environment. We've added some of the most notable ones here.

  • DevSecOps: Taking a DevOps Approach to Security
  • Mozilla's Test Driven Security in Continuous Integration
  • Security DevOps - staying secure in agile projects
  • Veracode's Defending the Cloud from a Full Stack Hack
  • Put Your Robots to Work: Security Automation at Twitter
  • The Three Faces of DevSecOps

Initiatives

There are a variety of initiatives underway to migrate security and compliance into DevOps. We've included links for active projects here:

  • AWS Labs
  • DevOps and Audit Resources
  • DevSecOps
  • OpenDevSecOps
  • Rugged DevOps

Keeping Informed

We've discovered a treasure trove of mailing lists and newsletters where DevSecOps like us are sharing their skills and insights.

  • AWS Security
  • Azure Security
  • Ruby Weekly
  • Security Newsletter
  • SRE Weekly

Wardley Maps for Security

One way for people to continue to evolve their capabilities and share common understanding is through the development of Wardley Maps. We're collecting this information and providing some good examples here.

  • Check out Figure 6 for Comparisons
  • DevSecOps Repo for Security Maps
  • Introduction to Wardley Maps
  • Security Industry Example
  • SOC Value Chain & Delivery Models

Training

DevSecOps requires an appetite for learning and agility to quickly acquire new skills. We've collected these links to help you learn how to do DevSecOps with us.

Labs

Labs are hands-on learning opportunities to grow your skills in Dev, Sec, and Ops. All skills are useful and need to be grown so that you can have the empathy, knowledge and trade to operate DevSecOps style.

  • DevSecOps Bootcamp
  • Exercism
  • Infoseclabs
  • Infrastructure Monitoring
  • Pentester Lab
  • Vulnhub

Vulnerable Test Targets

It's important to build up knowledge by learning how to break applications left vulnerable by security mistakes. This section contains a list of vulnerable apps that can be deployed to learn what not to do. These same apps can be made safe by remediating the intentional vulnerabilities to learn how to prevent attackers from gaining access to underlying infrastructure or data.

  • Damn Vulnerable Web Application (PHP/MySQL)
  • LambHack (Lambda)
  • Metasploitable (Linux)
  • Mutillidae (PHP)
  • NodeGoat (Node)
  • OWASP Damn Vulnerable Serverless Application (DVSA) (AWS Serverless)
  • OWASP Juice Shop (NodeJS/Angular)
  • RailsGoat (Rails)
  • WebGoat (Web App)
  • WebGoat.Net (.NET)
  • WebGoatPHP (PHP)

Conferences

A body of knowledge for combining DevOps and Security has been delivered via conferences and meetups. This is a short list of the venues that have dedicated a portion of their agenda to it.

Download Tool