
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Automated System Hardening Framework

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Simple and flexible tool for managing secrets

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…

A collection of awesome security hardening guides, tools and other resources

Open Source Cloud Native Application Protection Platform (CNAPP)

Multi-cloud security posture scanner that audits AWS, Azure, GCP, and OCI for misconfigurations, compliance violations (HIPAA, PCI, CIS), and…

An open source threat modeling tool from OWASP

GitHub App to set and enforce security policies

Superseded by https://github.com/aquasecurity/trivy-operator

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…