
kube-linter
KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

An open source, self-hosted implementation of the Tailscale control server

Library and CLI tool for analysing CloudFormation templates and check them for security compliance.

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Automating situational awareness for cloud penetration tests.

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

Boundary enables identity-based access management for dynamic infrastructure.

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors