
semgrep-rules
Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

Snyk CLI scans and monitors your projects for security vulnerabilities.

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

AWSGoat : A Damn Vulnerable AWS Infrastructure

kubeaudit helps you audit your Kubernetes clusters against common security controls

Security auditing tool for AWS environments

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…

PowerShell-based security assessment framework for Microsoft 365, Azure, and Entra ID. Scans for misconfigurations, CIS benchmark compliance, and…

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational…

RiskScanner 是开源的多云安全合规扫描平台,基于 Cloud Custodian 和 Nuclei 引擎,实现对主流公(私)有云资源的安全合规扫描和漏洞扫描。

AzureGoat : A Damn Vulnerable Azure Infrastructure

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

kube-scan: Octarine k8s cluster risk assessment tool

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

Discover resources created in an AWS account.