communitysec / sbom-hall-of-fameLinks
A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of material) to actually manage and reduce security risk in meaningful ways
☆43Updated 2 years ago
Alternatives and similar repositories for sbom-hall-of-fame
Users that are interested in sbom-hall-of-fame are comparing it to the libraries listed below
Sorting:
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆114Updated last week
- Supply-Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆214Updated this week
- Compares and analyzes GCP IAM roles.☆78Updated 10 months ago
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆60Updated last week
- ☆115Updated 5 months ago
- AWS honey token manager☆89Updated last year
- ## Auto-archived due to inactivity. ## Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Securit…☆37Updated last year
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆22Updated 2 years ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated 2 years ago
- A tool to check the security settings of Github Organizations.☆75Updated 2 years ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- Security Alert Decoration☆27Updated 6 months ago
- kntrl is an eBPF based runtime agent that monitors and prevents anomalous behaviour defined by you on your pipeline. kntrl achieves this …☆125Updated 3 months ago
- ☆14Updated 3 years ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆110Updated last year
- Scan GitHub Actions Workflow logs for IOCs☆16Updated last week
- An SBOM query language and associated utilities☆55Updated last year
- Automated testing, generation & manipulation of #osquery packs☆73Updated last year
- Knowledge Report Alert & Normalization Generator☆26Updated last month
- Useful scripts, Docker images, docker-compose apps, and Terraform modules.☆149Updated this week
- prel(iminary) is an application that temporarily assigns Google Cloud IAM Roles and includes an approval process.☆45Updated this week
- (D)ocker(F)ile (C)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆95Updated last week
- 💅🏽 analyzes your github actions☆97Updated 2 weeks ago
- vexctl is a tool to attest VEX impact statements☆45Updated 2 years ago
- https://breaches.cloud☆42Updated last year
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆177Updated last month
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆40Updated last year
- A Golang program to rotate AWS & GCP account keys☆66Updated 8 months ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆82Updated 3 years ago