communitysec / sbom-hall-of-fame
A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of material) to actually manage and reduce security risk in meaningful ways
☆42Updated 11 months ago
Related projects ⓘ
Alternatives and complementary repositories for sbom-hall-of-fame
- ☆107Updated last month
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆79Updated last week
- Compares and analyzes GCP IAM roles.☆76Updated 5 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆30Updated 3 weeks ago
- ☆16Updated 5 months ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- An SBOM query language and associated utilities☆54Updated 9 months ago
- Enrich SBOMs with data from third party services☆113Updated last week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- GCP CSPM using Google Sheets☆34Updated 5 months ago
- Automated testing, generation & manipulation of #osquery packs☆69Updated 3 weeks ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆93Updated 6 months ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆79Updated 2 years ago
- AWS honey token manager☆84Updated 3 months ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆37Updated last year
- PolicyGlass allows you to analyse one or more AWS policies' effective permissions in aggregate, by restating them in the form of PolicySh…☆58Updated 2 years ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆75Updated this week
- Audit log wall of shame.☆41Updated 3 weeks ago
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆57Updated last year
- Kubernetes audit logging, when you don't control the control plane☆65Updated this week
- Validate the isolation posture of your container environment.☆51Updated this week
- ☆51Updated 8 months ago
- ☆21Updated this week
- A tool to check the security settings of Github Organizations.☆69Updated last year
- ☆14Updated 2 years ago
- A Golang program to rotate AWS & GCP account keys☆65Updated 2 months ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆70Updated this week
- Format agnostic SBOM tooling☆78Updated this week
- A tool to create, transform and attest VEX metadata☆116Updated this week