
ccat
Modular penetration testing tool for cloud container environments. Enumerates ECR repositories, backdoors Docker images, and exploits…

Modular penetration testing tool for cloud container environments. Enumerates ECR repositories, backdoors Docker images, and exploits…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

OWASP Kubernetes security and compliance tool [WIP]

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Agentless platform for discovering and managing VM security threats including vulnerabilities, malware, rootkits, misconfigurations, leaked secrets,…

Kubernetes cluster risk assessment tool that scores workload configurations from 0-10 using the KCCSS framework. Scans 20+ runtime settings without…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

A Blazing fast Security Auditing tool for Kubernetes

Open-source, cross-platform, multi-purpose security auditing tool

Protocol-agnostic security kernel for AI tool execution. Enforces zero-trust, sandboxed isolation, policy-driven control, and full auditability…

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

Security-first wire protocol for agent coordination with mandatory mTLS, Ed25519-signed capability cards, Keycloak authentication, and per-call…

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.