
kube-linter
KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Linting tool for CloudFormation templates

Automation to assess the state of your M365 tenant against CISA's baselines

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption


A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…