
anchore-engine
A service that analyzes docker images and scans for vulnerabilities

A service that analyzes docker images and scans for vulnerabilities

Create a VPS on Google Cloud Platform or Digital Ocean easily with Offensive Docker included to launch assessment to the targets.

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

A tool for secrets management, encryption as a service, and privileged access management

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

Open source vulnerability DB and triage service.

Easily create full virtual machines that are sandboxed for development or computer use models.

Docker-based sandbox for coding agents with isolated environments, preinstalled agent tooling, service control, and workspace bootstrap for secure…

Knocker, a knock based access control service for your homelab

Service that scans your Infrastructure as Code for common vulnerabilities

Automated security checker for Kubernetes clusters with Istio service mesh, enforcing best practices via OPA policies and generating remediation…

OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML…

OPA Gatekeeper-based policy templates to mitigate CVE-2020-8554 by restricting Kubernetes Service external IPs to an allow list, preventing traffic…

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

A lightweight orchestrator and worker scanner setup for running large/continuous scans across split input files. This repository contains…

Community-driven knowledge base for pentesting cloud environments and CI/CD pipelines: attack techniques, enumeration, privilege escalation, and…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Give coding agents a disposable Linux VM, not your laptop