
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides…

a guard that blocks catastrophic agent actions

eBPF-powered Linux observability with AI incident detection. AGPL-3.0 licensed.

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

Powerful protection for AI agents - Open-source security and cost tracking for AI applications

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Open source vulnerability DB and triage service.

An open source threat modeling tool from OWASP

Documenting your Threat Models with HCL

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Automated vulnerability data aggregator that collects advisories from NVD, OSV, Alpine, Red Hat, and 20+ other sources into a unified parsable format…

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

Open source solutions for SOC2, GDPR, and ISO27001

Malicious package & supply-chain intelligence

MCP server for structured STRIDE-based threat modeling with automatic code validation, business context analysis, and comprehensive report generation…

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.