hupe1980 / cdk-threagile
Agile Threat Modeling as Code
☆13Updated 2 years ago
Alternatives and similar repositories for cdk-threagile:
Users that are interested in cdk-threagile are comparing it to the libraries listed below
- ☆22Updated last year
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 2 years ago
- Github Action implementation of SLSA Provenance Generation☆47Updated this week
- An SBOM query language and associated utilities☆54Updated 11 months ago
- ☆33Updated last year
- ☆21Updated last year
- Kubernetes audit logging, when you don't control the control plane☆67Updated this week
- A tool to check the security settings of Github Organizations.☆70Updated last year
- Service Control Policies that have been Latacora recommended all wrapped up in terraform that is easy to attach to an OU.☆22Updated 7 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- Slack alert bot for matching Github Audit Events☆10Updated 2 months ago
- Interrogate your GitHub resources with the help of the world's greatest detectives: Powerpipe + Steampipe + Sherlock.☆39Updated 2 months ago
- Force CloudFormation to generate a tree view for any stack☆18Updated 2 years ago
- Enrich SBOMs with data from third party services☆151Updated last week
- Mitigations (AWS WAF, Lambda@Edge/CloudFront Functions) to implement on AWS to attempt to prevent log4j exploitation.☆22Updated 3 years ago
- Safer AWS SCP deployments via real-time monitoring☆49Updated last year
- Lambda function for verifying signed images in ECS☆33Updated 10 months ago
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆46Updated 9 months ago
- The security workflow engine!☆92Updated this week
- serverless url-shortener☆11Updated 4 months ago
- Awesome AWS service control policies (SCPs)☆22Updated 2 months ago
- Open-source proof-of-concept client for AWS IAM Roles Anywhere☆71Updated 2 years ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆78Updated this week
- Centralizing AWS CloudWatch log forwarding via EventBridge and Step Functions☆49Updated last year
- A cloud security tool to search and clean up unused AWS access keys, written in Go.☆49Updated 2 years ago
- ☆40Updated 2 years ago
- Pre-commit git hooks for Open Policy Agent (OPA) and Rego development☆66Updated 2 years ago