Showing 36 of 148 projects
Collects assets and relationships from cloud, SaaS, and security systems into a Neo4j graph for security analysis.
A CLI tool that validates AWS IAM policies in Terraform templates against AWS IAM best practices and custom checks.
An AWS CDK construct to deploy, update, and stage Web Application Firewalls (WAFs) with central governance via AWS Firewall Manager.
Tools for vulnerability scanning and compliance auditing of Docker containers and images using OpenSCAP.
A Django web application for static security analysis (SAST) and malware detection in Android APKs.
A GitHub Action to upload and scan files for malware using VirusTotal's analysis engine.
A curated collection of threat modeling resources, including methodologies, tools, books, and conference talks.
A zero-code Kubernetes sidecar that redacts PII and secrets from application logs using entropy analysis and deterministic regex rules.
A research project inventorying RCE-by-design features and code execution risks in CI/CD pipeline tools.
A tool to verify scripts and executables by hash to prevent supply chain attacks.
A static analysis tool that spots security vulnerabilities in PostgreSQL extension scripts and SQL code.
A Python library to mock SSH servers and define custom commands for testing automation scripts.
A Python tool that scans codebases for potentially dangerous patterns like hardcoded passwords or accidental diff checkins.
A vulnerable-by-design CloudFormation template for learning and testing infrastructure-as-code security scanning tools.
A GitHub Action that runs tfsec with reviewdog on pull requests to enforce Terraform security best practices.
An open-source CLI scanner that finds AWS attack chains and provides copy-paste remediation with AWS CLI and Terraform.
A tool to detect which Go dependencies are vulnerable to GitHub repository hijacking (RepoJacking) attacks.
A lightweight static security analysis tool for modern Perl applications that identifies vulnerabilities using AST analysis and taint tracking.
OWASP's software composition analysis tool that identifies project dependencies and checks for known vulnerabilities.
A tool to detect and mitigate Dependency Confusion supply chain security risks in npm projects.
A methodology and toolset for creating reusable attack maps to integrate security threat modeling into software development workflows.
A security tool that scans GitLab repositories for secrets in dangling or force-pushed commits.
A proof-of-concept tool demonstrating and exploiting TOCTOU vulnerabilities in GitHub Actions approval workflows.
A prompt injection scanner for Claude Code hooks that detects attacks, leaked secrets, and data exfiltration using ML models.
A secure web gateway for controlled SQL query execution on PostgreSQL databases with OIDC authentication and OPA policy enforcement.
A GitHub Action that automatically lints AWS IAM policy documents for security issues and best practices.
A GitHub Action that scans Docker images for OS and library vulnerabilities in CI/CD pipelines.
A curated collection of resources for container building and runtime security.
A Go static analysis tool that detects accidental logging of sensitive struct fields tagged with `sensitive:"true"`.
Extracts network dependencies from application configs and generates Kubernetes NetworkPolicies for security and CI/CD.
AWS CDK constructs for defining threat models as code using the Threagile framework.
Demonstrates methods for sneaking malicious code into GitHub pull requests to raise awareness of supply chain vulnerabilities.
Scans Alpine Linux Docker images for Common Vulnerabilities and Exposures (CVEs) using multi-stage builds.
A Docker build security tool that restricts outbound network access to only allowed domains, preventing supply chain attacks.
A security tool for enumerating and exploiting pipeline vulnerabilities in GitHub Actions workflows and self-hosted runners.
GitHub Action that runs the dlint security linter on Python code to detect insecure coding patterns.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.