Showing 36 of 123 projects
A scanner that detects JavaScript libraries with known vulnerabilities and can generate a Software Bill of Materials (SBOM).
An open-source Cloud Security Posture Management (CSPM) tool that scans AWS, Azure, GCP, Oracle, and GitHub for security misconfigurations.
A 'Vulnerable by Design' cloud deployment tool for creating and completing capture-the-flag style security scenarios on AWS and Azure.
A comprehensive guide with diagrams and best practices for implementing corporate network segmentation across four security maturity levels.
A standalone tool that finds unprotected secrets like passwords and API keys in container images and file systems.
A universal secret manager CLI for developers that centralizes secrets from multiple providers and prevents secret sprawl.
Open source Runtime Application Self-Protection (RASP) solution that integrates security directly into application servers via instrumentation.
A security audit tool for Ruby projects that checks Gemfile.lock for vulnerable gem versions and insecure sources.
A static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.
Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.
KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.
A CLI tool that scans cloud infrastructure to detect, track, and alert on drift from Terraform IaC definitions.
A SpotBugs plugin for detecting security vulnerabilities in Java web and Android applications.
A deliberately vulnerable CI/CD environment with 11 challenges to learn and practice CI/CD security.
Automatically generate least-privilege IAM policies for AWS by specifying resource ARNs and access levels.
Automatically generate least-privilege IAM policies for AWS based on resource ARNs and access levels.
Security-focused static analysis tool for Elixir and Phoenix applications, detecting common vulnerabilities.
A curated list of threat modeling resources including books, courses, videos, tools, tutorials, and examples for learning and practicing threat modeling.
A curated list of DevSecOps tools, resources, and training materials for integrating security into the development lifecycle.
A machine learning security engine that preemptively prevents web app and API threats using supervised and unsupervised models.
A tool for quickly evaluating IAM permissions and identifying security risks in AWS accounts through graph-based analysis.
The largest open-source database of regex patterns for detecting secrets, API keys, passwords, and tokens in code.
Open-source supply chain security scanner that automatically detects vulnerabilities like Log4Shell in dependencies and notifies via GitHub pull requests.
An OWASP training app with 62 challenges demonstrating real-world secrets management mistakes and how to find them.
A GitHub App that continuously monitors and enforces security policies across organizations and repositories.
An AI-powered tool that analyzes source code to discover every endpoint, exposing shadow APIs and mapping the complete attack surface for security testing.
A linting tool that scans AWS CloudFormation templates for insecure infrastructure patterns and security violations.
Audits Python environments, requirements files, and dependency trees for known security vulnerabilities and can automatically fix them.
A vulnerable-by-design Terraform repository for learning cloud security misconfigurations across AWS, Azure, and GCP.
A tool for static vulnerability analysis and runtime monitoring of Docker images and containers to detect malware and anomalous activities.
A CLI tool that audits API specifications, validates OpenAPI compliance, and runs security tests to prevent undefined user behavior.
A static analyzer for Java that detects code quality issues, security vulnerabilities, and bugs with over 600 rules.
A CI/CD security agent that monitors GitHub Actions runners for threats like network egress, file integrity, and process activity.
A high-performance open-source secret scanner with live validation, blast radius mapping, and 700+ detection rules for code, Git, CI, cloud, and SaaS platforms.
A CLI tool for real-time malicious package detection and software supply chain security across multiple ecosystems.
AWS incident response runbook templates for DoS/DDoS attacks, credential leakage, and S3 bucket access incidents.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.