
falco
Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Open-source API security platform that inventories endpoints, detects sensitive data, identifies and blocks malicious traffic in real time, and…

Azure AD security assessment tool that evaluates tenant configuration and identity risk, scoring findings through a maturity framework to prioritize…

Spoofs the AWS IMDS endpoint to serve honey tokens, tricking attackers into using fake credentials that trigger alerts for blue-team detection in…

Generates and maintains Azure Sentinel parser for Sysmon events, normalizing all Windows endpoint telemetry into a searchable log schema via…

Proxy that guards MCP servers by screening tool calls for prompt injection, redacting secrets, enforcing policies, and detecting tool definition…

Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the…

Automation to assess the state of your M365 tenant against CISA's baselines

An open source threat modeling tool from OWASP

Cloud incident response and threat hunting tool that exports Azure, Entra ID, M365, and Defender telemetry for post-incident investigation and log…

PowerShell tool for enumerating and extracting files from SharePoint sites via Microsoft Graph. Generates detailed HTTP request logs for SIEM…

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…