contrastsecurity / contrastLinks
CodeSec by Contrast - The fastest and most accurate SAST scanner. Scan code and serverless environments
☆19Updated last year
Alternatives and similar repositories for contrast
Users that are interested in contrast are comparing it to the libraries listed below
Sorting:
- ☆37Updated 11 months ago
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments☆142Updated 6 months ago
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalation☆108Updated last year
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆108Updated 8 months ago
- Vulnerable by Design AWS Cloud Development Kit (CDK) Infrastructure☆47Updated last year
- An AWS metadata enumeration tool by Plerion☆96Updated last year
- ☆56Updated 2 years ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated 2 years ago
- Clean accounts over permissions in GCP infra at scale☆71Updated 2 years ago
- ☆50Updated last year
- A GitHub Actions Supply Chain CTF / Goat☆21Updated last week
- LLM Testing Findings Templates☆72Updated last year
- Protect against subdomain takeover☆92Updated last week
- This repository provides a comprehensive collection of Pulumi scenarios utilized by cnappgoat☆21Updated 5 months ago
- MetaHub is an automated contextual security findings enrichment and impact evaluation tool for vulnerability management.☆174Updated last week
- An experimental project using LLM technology to generate security documentation for Open Source Software (OSS) projects☆31Updated 4 months ago
- ☆140Updated 2 weeks ago
- InfoSec OpenAI Examples☆19Updated last year
- Nuclei plugins to audit Chrome extensions☆65Updated last year
- A tool to uncover undocumented APIs from the AWS Console.☆110Updated 2 months ago
- FrogPost: postMessage Security Testing Tool☆92Updated 2 months ago
- A web CTF for training developers in bug hunting and secure coding!☆99Updated 6 months ago
- find dangling domains in a multi cloud environment☆142Updated 3 weeks ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆42Updated last year
- A small tool to help developers understand a huge set of security requirements from appsec teams☆46Updated 2 years ago
- A tool for preventing the installation of malicious npm and PyPI packages☆152Updated last week
- ☆187Updated 3 months ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆122Updated 5 months ago
- ☆49Updated 2 years ago
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆40Updated 10 months ago