devops-kung-fu / lucha
A CLI that scans for sensitive data in source code
โ14Updated 2 years ago
Alternatives and similar repositories for lucha:
Users that are interested in lucha are comparing it to the libraries listed below
- ๐๏ธ STRIDE vs. ASVS equivalence tableโ76Updated 7 months ago
- An experimental project using LLM technology to generate security documentation for Open Source Software (OSS) projectsโ26Updated last month
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accountsโ61Updated last year
- Protect against subdomain takeoverโ93Updated 10 months ago
- Slack bot which promotes Defense in Depth/Zero Trust security practicesโ24Updated 2 years ago
- Compares and analyzes GCP IAM roles.โ77Updated 2 weeks ago
- โ110Updated last year
- Automate vulnerability triage which prioritizes remediation over discoveryโ16Updated this week
- Convert cloudtrail data to MITRE ATT&CK Sightingsโ79Updated 2 years ago
- A powerful tool that leverages AI to automatically generate comprehensive security documentation for your projectsโ58Updated 2 weeks ago
- boostsecurityio/lotpโ116Updated 2 weeks ago
- HashiCorp-relevant rules for the Semgrep code analysis toolโ39Updated last year
- โ63Updated 2 years ago
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrixโ58Updated last year
- Enriching the NVD CVSS scores to include Temporal & Threat Metricsโ174Updated this week
- An implementation of infrastructure-as-code scanning using dynamic tooling.โ56Updated 3 years ago
- Semgrep rules corresponding to the OWASP ASVS standardโ27Updated 4 years ago
- โ41Updated last month
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.โ40Updated last year
- Updated incident response generator for training classesโ43Updated 3 years ago
- GCP CSPM using Google Sheetsโ35Updated 9 months ago
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.โ30Updated 5 months ago
- A tool for preventing the installation of malicious PyPI and npm packagesโ130Updated this week
- Knowledge Report Alert & Normalization Generatorโ27Updated last year
- โ164Updated 6 months ago
- An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&CK insights, real-world incidents, references and securโฆโ146Updated last month
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ39Updated 3 months ago
- A Risk-Based Prioritization Taxonomy for prioritizing CVEs (Common Vulnerabilities and Exposures).โ73Updated 10 months ago
- AI featured threat modeling and security review actionโ43Updated 4 months ago
- GCP GOAT is the vulnerable application for learn the GCP Securityโ64Updated last year