
ftw
YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

agent runtime security - zero trust, zero setup, zero latency.

A macOS app to scan Xcode project files for possible security issues.

threatspec - continuous threat modeling, through code

Open-source alerting engine for time-series monitoring data. Connects to Prometheus, VictoriaMetrics, ElasticSearch, and other data sources. Supports…

OPNsense GUI, API and systems backend

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

Project Aura: Security auditing and code introspection

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Powershell-based bot framework