
kata-containers
Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

eBPF-powered Kubernetes monitoring and performance testing platform that automatically generates service maps, tracks real-time metrics, and runs…

Infrastructure as code for DNS!

A collection of scripts for assessing Microsoft Azure security

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

Discover resources created in an AWS account.

Open-source cloud security platform that discovers attack paths, identifies misconfigurations, visualizes IAM access, and provides step-by-step…

SSH bastion/jump host/jumpserver

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

Curated catalog of AWS resource types that can be publicly exposed, with CLI commands for creating and auditing public access configurations across…

DevSec SSH Baseline - InSpec Profile

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

DevSec Nginx Baseline - InSpec Profile

Like Envoy xDS, but for eBPF filters