javixeneize / zascaLinks
Yet Another SCA tool
☆13Updated 2 years ago
Alternatives and similar repositories for zasca
Users that are interested in zasca are comparing it to the libraries listed below
Sorting:
- A collection of 2020 artifacts describing the major pain points, vulnerabilities and concerns with Cloud Security.☆19Updated 4 years ago
- Vulnerable by Design AWS Cloud Development Kit (CDK) Infrastructure☆47Updated last year
- ☆41Updated last month
- CloudSplaining on AWS Managed Policies☆44Updated this week
- ☆10Updated 3 years ago
- Clean accounts over permissions in GCP infra at scale☆71Updated 2 years ago
- Tool for signing and verifying the integrity of CloudFormation templates☆15Updated 2 years ago
- ☆12Updated 4 years ago
- code reviews to practice☆16Updated 4 years ago
- Offensive Terraform Website☆45Updated 4 years ago
- A set of AWS resources for testing the Log4Shell vulnerability, deployable with terraform☆12Updated 3 years ago
- A very vulnerable implementation of a GraphQL API.☆16Updated 3 weeks ago
- ☆16Updated last year
- Assess certain AWS network configurations☆12Updated 7 years ago
- Interactive IPython Notebook to demonstrate OWASP ZAP's API and Scripting Functions - OWASP ZAP 2.8.0☆41Updated 2 years ago
- Threat model for Amazon S3 - Library of all the attack scenarios on Amazon S3, and how to mitigate them following a risk-based approach☆157Updated last year
- CDK app to setup an isolated AWS network to experiment with ways of exfiltrating data☆18Updated 3 years ago
- ☆14Updated 2 years ago
- Lightspin AWS IAM Vulnerability Scanner☆96Updated 4 years ago
- A walkthrough of security controls for a serverless architecture via a demo application☆12Updated 3 years ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆66Updated 2 months ago
- AWS Quick Start Team☆16Updated 10 months ago
- Given a list of domains and known IP and buckets that are owned, which might be susceptible to domain hijacking?☆14Updated 11 months ago
- Application Security Workflow Automation using Docker and Kubernetes☆22Updated 2 years ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated 2 years ago
- https://breaches.cloud☆42Updated 10 months ago
- A small tool to help developers understand a huge set of security requirements from appsec teams☆47Updated 3 years ago
- Slack alert bot for matching Github Audit Events☆10Updated 9 months ago
- A framework for understanding the capabilities of automated detection methods at identifying classes of application security vulnerabilit…☆30Updated this week
- Curated list of security tools☆68Updated last year