There are 75 repositories under devsecops topic.
Scanner for vulnerabilities in container images, file systems, and Git repositories, as well as for configuration issues and hard-coded secrets
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Protect and discover secrets using Gitleaks 🔑
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
Prowler is an Open Source security tool to perform AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It contains more than 240 controls covering CIS, PCI-DSS, ISO27001, GDPR, HIPAA, FFIEC, SOC2, AWS FTR, ENS and custom security frameworks.
Security scanner for your Terraform code
Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
Ultimate DevSecOps library
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
DefectDojo is a DevSecOps and vulnerability management tool.
nodejsscan is a static security code scanner for Node.js applications.
Centralize Vulnerability Assessment and Management for DevSecOps Team
🌙🦊 DalFox is an powerful open source XSS scanning tool and parameter analyzer, utility
🔥 🔥 Open source cloud native security observability platform. Linux, K8s, AWS Fargate and more. 🔥 🔥
:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
LunaSec - Open Source AppSec platform that automatically notifies you the next time vulnerabilities like Log4Shell or node-ipc happen. Track your dependencies and builds in a centralized service. Get started in one-click via our GitHub App or host it yourself. https://github.com/apps/lunatrace-by-lunasec/
Detect secrets in source code, scan git repos, and use pre commit hooks to prevent API key leaks.
Checklist for container security - devsecops practices
This repo includes Books and imp notes related to GCP, Azure, AWS, Docker, K8s, and DevOps. More, exam and interview prep notes.
CMS Scanner: Scan Wordpress, Drupal, Joomla, vBulletin websites for Security issues
This is a step-by-step guide to implementing a DevSecOps program for any size organization
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
Awesome PHP Security Resources 🕶🐘🔐
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
kube-scan: Octarine k8s cluster risk assessment tool
OpenSCA is a Software Composition Analysis (SCA) solution that supports detection of open source component dependencies and vulnerabilities.
Curating the best DevSecOps resources and tooling.