
bmcweb
A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC

A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC

Curated timeline of AWS S3 bucket misconfigurations, exposed data, and leaked IAM credentials, with incident links for cloud security defenders and…

Audits Azure AD and Exchange Online configurations for hard-to-find permissions, federation trusts, mail forwarding rules, and delegated access to…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

Library and CLI tool for analysing CloudFormation templates and check them for security compliance.

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Tooling for assessing an Azure AD tenant state and configuration

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

This chef cookbook provides secure ssh-client and ssh-server configurations.

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…