Skyscanner / whispers
Identify hardcoded secrets in static structured text
☆478Updated last year
Alternatives and similar repositories for whispers:
Users that are interested in whispers are comparing it to the libraries listed below
- OWASP Domain Protect - prevent subdomain takeover☆401Updated last month
- Scan your code for security misconfiguration, search for passwords and secrets.☆639Updated last year
- Find secrets in your codebase☆122Updated 3 weeks ago
- Private key usage verification☆421Updated last month
- Threat matrix for CI/CD Pipeline☆743Updated 6 months ago
- Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependenci…☆822Updated last year
- Open Cloud Security Posture Management Engine☆336Updated 2 years ago
- Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.☆536Updated 2 weeks ago
- all paths lead to clouds☆635Updated last year
- A suite of secret scanners built in Rust for performance. Based on TruffleHog (https://github.com/dxa4481/truffleHog) which is written in…☆465Updated 3 weeks ago
- FestIn - Open S3 Bucket Scanner☆230Updated 4 years ago
- Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.☆267Updated 4 months ago
- Evaluate source control (GitHub) security posture☆249Updated last year
- boostsecurityio/poutine☆244Updated 2 weeks ago
- Documenting your Threat Models with HCL☆413Updated 4 months ago
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆788Updated last week
- Open source compliance tool for development platforms.☆287Updated last year
- A honey token manager and alert system for AWS.☆316Updated 3 years ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆153Updated 5 months ago
- An AWS Pentesting tool that lets you use one-liner commands to backdoor an AWS account's resources with a rogue AWS account - or share th…☆267Updated 3 years ago
- Cloudlist is a tool for listing Assets from multiple Cloud Providers.☆896Updated this week
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆147Updated 4 years ago
- A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure☆678Updated last year
- Slack enumeration and exposed secrets detection tool☆370Updated last month
- A container analysis and exploitation tool for pentesters and engineers.☆655Updated last year
- A tool for quickly evaluating IAM permissions in AWS.☆1,447Updated 5 months ago
- Kubernetes focused container assessment and context discovery tool for penetration testing☆444Updated 7 months ago
- A graph-based tool for visualizing effective access and resource relationships in AWS environments.☆933Updated 2 years ago
- Uncover forgotten secrets and bring them back to life, haunting security and operations teams.☆207Updated last year
- Yar is a tool for plunderin' organizations, users and/or repositories.☆233Updated 4 years ago