communitysec / sbom-hall-of-fameLinks
A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of material) to actually manage and reduce security risk in meaningful ways
☆42Updated last year
Alternatives and similar repositories for sbom-hall-of-fame
Users that are interested in sbom-hall-of-fame are comparing it to the libraries listed below
Sorting:
- Compares and analyzes GCP IAM roles.☆77Updated 2 months ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆110Updated this week
- ☆112Updated last week
- A tool for preventing the installation of malicious PyPI and npm packages☆145Updated this week
- (d)ocker(f)ile (c)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆65Updated this week
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆98Updated 5 months ago
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆39Updated 9 months ago
- AWS honey token manager☆87Updated 10 months ago
- ☆54Updated this week
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆55Updated 4 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- Adversary emulation for EDR/SIEM testing (macOS/Linux)☆43Updated last year
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆57Updated 11 months ago
- An SBOM query language and associated utilities☆54Updated last year
- A tool to check the security settings of Github Organizations.☆71Updated last year
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆31Updated 7 months ago
- https://breaches.cloud☆39Updated 7 months ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated last year
- Scan GitHub Actions Workflow logs for IOCs☆15Updated this week
- Automate vulnerability triage which prioritizes remediation over discovery☆18Updated this week
- PolicyGlass allows you to analyse one or more AWS policies' effective permissions in aggregate, by restating them in the form of PolicySh…☆59Updated 3 years ago
- Knowledge Report Alert & Normalization Generator☆27Updated last year
- prel(iminary) is an application that temporarily assigns Google Cloud IAM Roles and includes an approval process.☆44Updated this week
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- Automated testing, generation & manipulation of #osquery packs☆73Updated 7 months ago
- TrailAlerts is a AWS-native, serverless cloud-detection tool that lets you define simple rules as code and get rich alerts about events i…☆43Updated last month
- GCP CSPM using Google Sheets☆36Updated 2 months ago
- ☆48Updated 7 months ago
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆58Updated last year