
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

a static analysis tool for finding vulnerabilities in C/C++ source code

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

CLI tool to scan codebases for quantum-vulnerable cryptography

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Linting tool for CloudFormation templates

AWS Serverless Security

Open-source, cross-platform, multi-purpose security auditing tool

A static analysis tool for securing Go code

UT based automated fuzz driver generation