Checkmarx / kics
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
☆2,140Updated this week
Alternatives and similar repositories for kics:
Users that are interested in kics are comparing it to the libraries listed below
- Tfsec is now part of Trivy☆6,746Updated this week
- Detect, track and alert on infrastructure drift☆2,495Updated last week
- Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.☆4,802Updated last month
- Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google Cloud, and Kubernetes se…☆961Updated 4 months ago
- Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependenci…☆822Updated last year
- OpenClarity is an open source tool built to enhance security and observability of cloud native applications and infrastructure☆1,367Updated this week
- Security risk analysis for Kubernetes resources☆1,265Updated this week
- Hunt for security weaknesses in Kubernetes clusters☆4,781Updated 9 months ago
- Moved to https://github.com/aquasecurity/trivy-operator☆1,360Updated last month
- A Blazing fast Security Auditing tool for Kubernetes☆992Updated 9 months ago
- A service that analyzes docker images and scans for vulnerabilities☆1,587Updated last year
- Kubernetes Security Training Platform - focusing on security mitigation☆938Updated 4 months ago
- Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark☆7,186Updated this week
- Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities☆861Updated last week
- Read your tfstate or HCL to generate a graph specific for each provider, showing only the resources that are most important/relevant.☆1,781Updated 7 months ago
- Threat matrix for CI/CD Pipeline☆743Updated 6 months ago
- Write tests against structured configuration data using the Open Policy Agent Rego query language☆2,902Updated this week
- An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchm…☆735Updated last month
- A curated list of awesome Kubernetes security resources☆907Updated last year
- A tool to scan Kubernetes cluster for risky permissions☆1,340Updated last month
- ☆502Updated this week
- Supply-chain Levels for Software Artifacts☆1,580Updated this week
- 🧵 CLI tool for directly patching container images!☆1,110Updated this week
- ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring su…☆968Updated this week
- Reads from existing public and private cloud providers (reverse Terraform) and generates your infrastructure as code on Terraform configu…☆2,229Updated 8 months ago
- Kubernetes-native security toolkit☆1,340Updated this week