
spire
Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Automating situational awareness for cloud penetration tests.

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Library and CLI tool for analysing CloudFormation templates and check them for security compliance.

Declarative DNS management tool with a JavaScript-compatible DSL for automating DNS record changes across 64+ providers, enabling GitOps workflows…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

AWS IAM security assessment tool that scans policies for least-privilege violations, identifies data exfiltration, privilege escalation, and…

A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC

Identity-aware proxy providing secure, just-in-time access to hosts with session controls, dynamic credential management, and OIDC integration.

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…