
certbot
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

The easiest, and most secure way to access and protect all of your infrastructure.

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Automation to assess the state of your M365 tenant against CISA's baselines

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

Validation of best practices in your Kubernetes clusters

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

HardeningKitty - Checks and hardens your Windows configuration

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational…

Open source templates you can use to bootstrap your security programs

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

A security auditor for Tailscale configurations. Scans your tailnet for misconfigurations, overly permissive access controls, and security best…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

Harden your package manager configs against supply chain attacks.

An ADCS honeypot to catch attackers in your internal network.