
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Automated System Hardening Framework

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Simple and flexible tool for managing secrets

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

A collection of awesome security hardening guides, tools and other resources

Open Source Cloud Native Application Protection Platform (CNAPP)

Multi-cloud security posture scanner that audits AWS, Azure, GCP, and OCI for misconfigurations, compliance violations (HIPAA, PCI, CIS), and…

An open source threat modeling tool from OWASP

GitHub App to set and enforce security policies

Superseded by https://github.com/aquasecurity/trivy-operator

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

A security auditor for Tailscale configurations. Scans your tailnet for misconfigurations, overly permissive access controls, and security best…

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…