
burpa
Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Public OCI-Image (docker image) Security Checker

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Draw.io libraries for threat modeling diagrams

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

The easiest, and most secure way to access and protect all of your infrastructure.

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Gradle plugin for fast, reproducible Eclipse IDE provisioning as a build artifact, with support for OSGi, p2, and RCP builds.

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

Identify hardcoded secrets in static structured text

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.