ManicodeSecurity / Defending-DevOpsLinks
Lab Material for the Two-Day Defending Modern DevOps Environments Course
☆126Updated 6 years ago
Alternatives and similar repositories for Defending-DevOps
Users that are interested in Defending-DevOps are comparing it to the libraries listed below
Sorting:
- OWASP Cloud Security - Enabling conversations through threat and control stories☆182Updated 7 years ago
- Security aspects of AWS products for the Security Specialist certification☆211Updated 3 years ago
- ☆51Updated 5 years ago
- This repo gives an overview of some GCP metadata API attack and defend patterns☆78Updated 5 years ago
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulne…☆31Updated 3 years ago
- A very vulnerable serverless application in AWS Lambda☆98Updated 6 years ago
- Security scanning & static analysis tool☆93Updated last year
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆134Updated 5 years ago
- ☆69Updated 6 months ago
- ☆57Updated 5 years ago
- k8s audit repo☆229Updated 6 years ago
- Kubernetes Easter CTF☆59Updated 5 years ago
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 5 years ago
- Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities☆136Updated 3 years ago
- ☆74Updated 5 years ago
- A deliberately vulnerable Kubernetes cluster☆131Updated 2 years ago
- Presentations, training modules, and other education materials from Duo Security's Application Security team.☆76Updated 4 years ago
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.☆64Updated 6 years ago
- ☆124Updated 2 years ago
- Research on the enumeration of IAM permissions without logging to CloudTrail☆61Updated 4 years ago
- AppSecPipeline Specification for DevOps automation.☆40Updated 3 years ago
- Repo to hold the markdown-ified metadata on AppSec tools that are automation-friendly☆12Updated 9 years ago
- ☆269Updated 3 weeks ago
- Monitors Github for leaked secrets☆205Updated last year
- 🖇️ equivalence table between OWASP ASVS standard and STRIDE threat modeling methodology.☆76Updated last year
- Pentester-focused Docker registry tool to enumerate and pull images☆112Updated 6 years ago
- for AWS Security material☆249Updated 3 years ago
- Cloud-related research releases from the Rhino Security Labs team.☆392Updated 5 years ago
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆102Updated 6 years ago
- ☆27Updated 4 months ago