Showing 36 of 36 projects
A security auditing and hardening tool for UNIX-based systems, performing in-depth scans and compliance testing.
An open-source unified XDR and SIEM platform for threat prevention, detection, and response across endpoints and cloud workloads.
An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.
An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.
Open source platform for creating, filling, and signing digital documents with an easy-to-use, mobile-optimized web tool.
An open-source, general-purpose policy engine for unified, context-aware policy enforcement across the stack.
A generic and open signature format for describing log event detections, shareable across SIEM systems.
A script that checks for dozens of common best-practices around deploying Docker containers in production.
An immutable database with built-in cryptographic proof and verification, supporting SQL, Key-Value, and Document models.
A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.
A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.
A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.
A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
Open-source platform for IT and security teams to manage and secure thousands of computers across diverse environments.
A curated collection of security hardening guides, best practices, checklists, benchmarks, and tools for various systems and services.
A rules engine for cloud security, cost optimization, and governance using YAML policies to query, filter, and act on cloud resources.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
Open Source Host-based Intrusion Detection System performing log analysis, file integrity checking, rootkit detection, and active response.
A PHP implementation for validating JSON structures against JSON Schema drafts 3, 4, 6, and 7.
An ActiveRecord extension for Rails that logs all changes to your models, including who made them and why.
A Laravel package that records change logs from Eloquent models to track discrepancies and anomalies.
Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.
A static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.
KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.
Open-source infrastructure and data orchestration platform for risk decisioning, automating KYC, KYB, underwriting, and transaction monitoring.
The OWASP Mobile Application Security Verification Standard (MASVS) is the industry standard for mobile app security.
A developer platform for building compliant healthcare applications with FHIR standards, authentication, and clinical data management.
A production-ready auditd configuration for Linux security monitoring that works out-of-the-box across major distributions.
A command-line toolkit for validating, scanning, and managing SCAP (Security Content Automation Protocol) documents.
An open-source tool for PostgreSQL and MySQL database anonymization, synthetic data generation, and logical dumping.
An open-source artifact metadata API for auditing and governing software supply chains.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.