
firecracker
Secure and fast microVMs for serverless computing.

Secure and fast microVMs for serverless computing.

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Boundary enables identity-based access management for dynamic infrastructure.

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

eBPF-powered Kubernetes monitoring and performance testing platform that automatically generates service maps, tracks real-time metrics, and runs…

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

Automating situational awareness for cloud penetration tests.

Hunt for security weaknesses in Kubernetes clusters

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

Attack Surface Management since before Attack Surface Management was a thing

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

AWS Identity and Access Management Visualizer and Anomaly Finder

Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

An AWS IAM policy statement parser and query tool.