
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

a static analysis tool for finding vulnerabilities in C/C++ source code

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.