communitysec / sbom-hall-of-fameLinks
A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of material) to actually manage and reduce security risk in meaningful ways
☆42Updated last year
Alternatives and similar repositories for sbom-hall-of-fame
Users that are interested in sbom-hall-of-fame are comparing it to the libraries listed below
Sorting:
- A tool for preventing the installation of malicious npm and PyPI packages☆152Updated this week
- Compares and analyzes GCP IAM roles.☆77Updated 4 months ago
- ☆113Updated last week
- Useful scripts, Docker images, docker-compose apps, and Terraform modules.☆150Updated this week
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆31Updated 9 months ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆110Updated last week
- A tool to check the security settings of Github Organizations.☆72Updated 2 years ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated last year
- AWS honey token manager☆87Updated 11 months ago
- A Golang program to rotate AWS & GCP account keys☆66Updated 2 months ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆173Updated 7 months ago
- Knowledge Report Alert & Normalization Generator☆27Updated last year
- (d)ocker(f)ile (c)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆79Updated 2 weeks ago
- Audit log wall of shame.☆41Updated 9 months ago
- Documenting your Threat Models with HCL☆432Updated last month
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆57Updated last year
- Scan GitHub Actions Workflow logs for IOCs☆15Updated this week
- ☆116Updated last week
- https://breaches.cloud☆41Updated 9 months ago
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆58Updated last year
- Convert cloudtrail data to MITRE ATT&CK Sightings☆80Updated 2 years ago
- Automated testing, generation & manipulation of #osquery packs☆73Updated 9 months ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆106Updated 6 months ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated 2 years ago
- Security Alert Decoration☆27Updated 2 months ago
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆40Updated 10 months ago
- The security workflow engine!☆118Updated this week
- Automate vulnerability triage which prioritizes remediation over discovery☆19Updated last week
- ☆55Updated 2 weeks ago