aquasecurity / defsec
Trivy's misconfiguration scanning engine
☆218Updated 3 weeks ago
Alternatives and similar repositories for defsec:
Users that are interested in defsec are comparing it to the libraries listed below
- Static Analysis Library for Containers☆199Updated last year
- Security configuration checks for popular cloud native applications and infrastructure.☆118Updated 2 years ago
- Notice: Postee is no longer under active development or maintenance.☆210Updated this week
- Evaluate the RBAC permissions of Kubernetes identities through policies written in Rego☆343Updated last year
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆123Updated this week
- ☆92Updated last week
- CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.☆272Updated 5 months ago
- a tool to audit the istio service mesh☆174Updated 3 years ago
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆80Updated last year
- Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.☆162Updated last year
- An open project to list all publicly known cloud vulnerabilities and CSP security issues☆317Updated 3 weeks ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆79Updated last month
- Documenting your Threat Models with HCL☆419Updated 5 months ago
- Runtime security plug to protect user containers☆65Updated this week
- Create Kubernetes AdmissionReview requests from Kubernetes resource manifests☆112Updated 3 weeks ago
- Falco plugins registry☆87Updated this week
- Generate a variety of suspect actions that are detected by Falco rulesets☆101Updated this week
- A utility to generate SPDX-compliant Bill of Materials manifests☆365Updated last week
- Falco rule repository☆107Updated last week
- ☆46Updated this week
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 2 years ago
- Cloud Native Security Hub - Security Resources☆54Updated 4 years ago
- A curated list of policy-as-code resources like blogs, videos, and tools to practice on for learning Policy-as-Code.☆186Updated last year
- Open source compliance tool for development platforms.☆286Updated last year
- This repo is a consolidation of Secure Software Supply Chain resources, such as talks, whitepapers, conferences and more.☆137Updated 2 years ago
- All-in-one auditing toolkit for identifying common security issues in managed Kubernetes environments. Currently supports Amazon EKS.☆333Updated last year
- Kubernetes focused container assessment and context discovery tool for penetration testing☆448Updated 7 months ago
- A VS Code Extension for Trivy☆119Updated this week
- Cloud Security Posture security policies☆29Updated 5 months ago
- A Cloud Security Posture Manager or CSPM with a focus on security analysis for the modern cloud stack and a focus on the emerging threat …☆179Updated 5 months ago