kosli-dev / secure-sdlc-process-template
Secure SDLC process template
☆50Updated 6 months ago
Related projects ⓘ
Alternatives and complementary repositories for secure-sdlc-process-template
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Updated 2 years ago
- A Software as a Service (SaaS) log collection framework.☆130Updated 3 weeks ago
- CLI that scans directories for Cloud Provider SDK usage generates the IAM Policies/Permissions needed☆73Updated last month
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆79Updated last week
- CLI to prevent malicious Terraform Providers from being executed. You can define the allow list of Terraform Providers and their versions…☆75Updated this week
- A Golang program to rotate AWS & GCP account keys☆65Updated 2 months ago
- AWS honey token manager☆84Updated 3 months ago
- Scalable integrity framework for ABAC on AWS☆29Updated last week
- Template SOC2 Policy Authority - documentation pipeline☆99Updated 4 years ago
- A list of cloud security tools and vendors.☆135Updated 2 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆57Updated last year
- Automate permissions to your cloud and critical applications.☆238Updated 8 months ago
- Evaluate source control (GitHub) security posture☆249Updated last year
- ☆140Updated 4 months ago
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆140Updated 2 weeks ago
- ☆111Updated 2 weeks ago
- Is your AWS perimeter secure? Use Powerpipe and Steampipe to check your AWS accounts for public resources, resources shared with untrust…☆106Updated 3 weeks ago
- prel(iminary) is an application that temporarily assigns Google Cloud IAM Roles and includes an approval process.☆36Updated this week
- This repo is a consolidation of Secure Software Supply Chain resources, such as talks, whitepapers, conferences and more.☆137Updated 2 years ago
- Generate datasets of cloud audit logs for common attacks☆183Updated 3 months ago
- Documenting SOC 2 tools and processes☆70Updated 2 years ago
- IAMbic is Version-Control for IAM. It centralizes and simplifies cloud access and permissions. It maintains an eventually consistent, hum…☆285Updated 3 months ago
- ☆16Updated 6 months ago
- Documenting your Threat Models with HCL☆400Updated 2 months ago
- ☆203Updated last month
- ☆22Updated last year
- KaiMonkey provides vulnerable infrastructure as code (IaC) to help explore and understand common cloud security threats exposed via IaC.☆96Updated 10 months ago
- A tool for quickly evaluating IAM permissions in AWS.☆70Updated 5 months ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆79Updated 2 years ago
- Clean accounts over permissions in GCP infra at scale☆71Updated last year