
Cowrie and Grafana Honeypot using Terraform on DigitalOcean
Medium-interaction SSH/Telnet honeypot built with Cowrie, Loki, Promtail, and Grafana - provisioned on DigitalOcean via Terraform with a GitLab CI…

Medium-interaction SSH/Telnet honeypot built with Cowrie, Loki, Promtail, and Grafana - provisioned on DigitalOcean via Terraform with a GitLab CI…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

Write tests against structured configuration data using the Open Policy Agent Rego query language

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

🛡️ 🔒 This project's goal is to be simple to create and destroy your own VPN service using WireGuard.

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

System utility that identifies and restarts daemons using outdated libraries after package upgrades to maintain security. Supports containers and…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

AI-powered offensive security testing using autonomous agents, directly in your terminal.

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Go library for safe YAML and shell generation, using syntax-aware templates to detect and block injection attacks via annotations for trusted data.