carbonetes / brainiac
BrainIAC uses static code analysis to analyze IAC code to detect security issues before deployment. This tool can scan for issues like security policy misconfigurations, insecure cloud-based services, and compliance issues.
☆68Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for brainiac
- A Github Action that utilizes Diggity to generate software bill-of-materials (SBOM).☆14Updated last year
- Generates SBOMs for container images, filesystems, archives, and more to Discover packages and libraries Highly scalable data pipelines f…☆102Updated 2 months ago
- Jacked provides organizations with a more comprehensive look at their application to take calculated actions and create a better security…☆100Updated 2 months ago
- ☆18Updated 3 months ago
- ☆34Updated last year
- OWASP Foundation Web Respository☆16Updated 3 weeks ago
- NIST SP 800-171 OSCAL Content☆13Updated 2 years ago
- Agile authoring tutorial and repo set-up tooling☆18Updated 2 months ago
- Stakeholder-Specific Vulnerability Categorization☆130Updated this week
- Mitre ATT&CK framework tactics and techniques in markdown format for best use in Obsidian☆16Updated 3 months ago
- Terraform modules for Sumo Logic resources☆14Updated 2 months ago
- US Government controls formatted for usability☆17Updated 3 years ago
- A project to visualize the software supply chain☆36Updated last year
- Autoconfigured ELK Stack That Contains All EPSS and NVD CVE Data☆47Updated 4 months ago
- Gatecheck CI/CD Validation Tool☆14Updated 5 months ago
- Secure Jupyter Notebooks and Experimentation Environment☆56Updated last month
- A Risk-Based Prioritization Taxonomy for prioritizing CVEs (Common Vulnerabilities and Exposures).☆68Updated 6 months ago
- Offensive Terraform Website☆44Updated 4 years ago
- A tool for quickly evaluating IAM permissions in AWS.☆70Updated 5 months ago
- An AI-powered tool for discovering privilege escalation opportunities in AWS IAM configurations.☆96Updated last month
- Skyflow SDK for the Go programming language.☆11Updated this week
- Posture Attribute Collection and Evaluation☆23Updated last year
- A lightweight library to sanitize data provided to AI tools☆26Updated last year
- Public static website for the D3FEND project. For the D3FEND ontology repo see: https://github.com/d3fend/d3fend-ontology☆73Updated 3 weeks ago
- PEACH - a step-by-step framework for modeling and improving SaaS and PaaS tenant isolation, by managing the attack surface exposed by use…☆65Updated last year
- Java libraries for working with available vulnerability data sources (GitHub Security Advisories, NVD, EPSS, CISA Known Exploited Vulnera…☆124Updated this week
- Docs: Vulnerability management aggregation of AppSec & OpSec (Tools Listing)☆30Updated last year
- CVSS2/3/4 library with interactive calculator for Python 2 and Python 3☆87Updated 3 weeks ago
- Enriching the NVD CVSS scores to include Temporal & Threat Metrics☆61Updated this week
- DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.☆36Updated 3 years ago