
wazuh
Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

A vulnerability scanner for container images and filesystems

Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

Anti-Virus for K8s. Protect your Applications running on Kubernetes from malicious attacks with pre-registered source code, runtime processes…

Linux application sandboxing and distribution framework

Branchable computing by using a portable, lightweight, self-contained virtual machine

Secure and fast microVMs for serverless computing.

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…