
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from…

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

Snyk CLI scans and monitors your projects for security vulnerabilities.

Scalable fuzzing infrastructure with coverage-guided engines (libFuzzer, AFL, Honggfuzz), automated crash deduplication, bug filing, and regression…

This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

Hardened, Azure-optimized Linux distribution built from Fedora sources with RPM packaging, supply chain security, and declarative configuration for…

Infrastructure as code for DNS!

Open source vulnerability DB and triage service.

Generates least-privilege AWS IAM policies based on resource ARNs and access levels, automating secure policy creation for cloud infrastructure.

kubeaudit helps you audit your Kubernetes clusters against common security controls

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

LLM powered fuzzing via OSS-Fuzz.

PacBot (Policy as Code Bot)

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational…