ochronasec / ochrona-cli
A command line tool for detecting vulnerabilities in Python dependencies and doing safe package installs
☆52Updated last year
Alternatives and similar repositories for ochrona-cli:
Users that are interested in ochrona-cli are comparing it to the libraries listed below
- Static security checker for Dockerfiles☆93Updated 9 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆59Updated 6 months ago
- Hayat is a script for report and analyze Google Cloud Platform resources.☆79Updated 5 years ago
- Dependency Combobulator☆89Updated last year
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆76Updated 4 years ago
- ☆10Updated 2 years ago
- Scan DockerHub images that match a keyword to find secrets.☆55Updated 3 years ago
- Clean accounts over permissions in GCP infra at scale☆71Updated last year
- 🖇️ STRIDE vs. ASVS equivalence table☆75Updated 4 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆37Updated last month
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆138Updated 3 years ago
- ZAP Management Scripts☆21Updated last week
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆75Updated 2 years ago
- A curated list of security tools for Hackers & Builders!☆98Updated 5 months ago
- Monitoring GitHub for sensitive data shared publicly☆66Updated 3 years ago
- ☆36Updated 3 years ago
- Scan your EC2 instance to find its vulnerabilities using Vuls (https://vuls.io/en/)☆88Updated 2 years ago
- ☆110Updated last year
- All-in-one tool for managing vulnerability reports from AppSec pipelines☆105Updated 2 years ago
- AWS SSO serverless phishing API.☆31Updated 3 years ago
- Static Token And Credential Scanner☆95Updated last year
- sgCheckup generates nmap output based on scanning your AWS Security Groups for unexpected open ports.☆81Updated 3 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Updated 2 years ago
- Security tools report parsers for Faradaysec.com☆51Updated last week
- ☆30Updated last year
- A small library to alter AWS API requests; Used for fuzzing research☆21Updated last year
- Offensive Terraform Website☆44Updated 4 years ago
- Scans Slack for API tokens, credentials, passwords, and more using YARA rules☆38Updated 3 years ago
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Updated last year