Showing 32 of 32 projects
A fast, customizable vulnerability scanner with a YAML-based DSL, powered by a global security community.
A secrets scanning tool that discovers, classifies, validates, and analyzes leaked credentials across multiple sources.
A secrets scanning tool that discovers, classifies, validates, and analyzes leaked credentials across multiple sources.
An open-source unified XDR and SIEM platform for threat prevention, detection, and response across endpoints and cloud workloads.
An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.
An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.
A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.
A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.
An open-source multi-cloud security auditing tool that assesses cloud environment security posture via provider APIs.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
Open-source data pipelines to sync cloud infrastructure metadata from AWS, Azure, GCP, and 70+ sources into your data warehouse.
A rules engine for cloud security, cost optimization, and governance using YAML policies to query, filter, and act on cloud resources.
An intentionally vulnerable Kubernetes cluster environment for hands-on security training and practice.
Open source CNAPP that hunts for threats in cloud native platforms, ranks them by risk, and visualizes attack paths.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
Monitors AWS, GCP, OpenStack, and GitHub for policy changes and insecure configurations, tracking asset changes over time.
An open-source, cloud-agnostic tool to analyze and manage cloud cost, usage, security, and governance across multiple providers.
A Python tool that pulls infrastructure assets and relationships from AWS, GCP, Azure, and 30+ other platforms into a Neo4j graph for security analysis.
An open-source Cloud Security Posture Management (CSPM) tool that scans AWS, Azure, GCP, Oracle, and GitHub for security misconfigurations.
A 'Vulnerable by Design' cloud deployment tool for creating and completing capture-the-flag style security scenarios on AWS and Azure.
A CLI tool that scans cloud infrastructure to detect, track, and alert on drift from Terraform IaC definitions.
KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.
A curated list of resources covering Identity and Access Management (IAM) for cloud platforms, including authentication, authorization, and security.
A curated list of resources covering Identity and Access Management (IAM) for cloud platforms, including authentication, authorization, and security.
Automatically generate least-privilege IAM policies for AWS by specifying resource ARNs and access levels.
Automatically generate least-privilege IAM policies for AWS based on resource ARNs and access levels.
An open source, serverless security data lake for AWS that normalizes logs, enables detection-as-code, and supports petabyte-scale threat hunting.
A tool for quickly evaluating IAM permissions and identifying security risks in AWS accounts through graph-based analysis.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.