samvas-codes / cspm-gpt
The following is a simple example of how LLMs and langchain agents can simplify asking questions to understand the security posture of a cloud environment.
☆20Updated last year
Related projects ⓘ
Alternatives and complementary repositories for cspm-gpt
- Based on Lightspin proprietary data, research, and our tracking of cloud security trends in the market, our research team has compiled a …☆39Updated 2 years ago
- A penetration toolkit for container environment☆76Updated 2 months ago
- Simple source code security audit helper☆50Updated 4 months ago
- ☆30Updated last year
- ☆79Updated 7 months ago
- ☆147Updated last year
- k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.☆279Updated 3 years ago
- Low-level RASP: Protecting Applications Implemented in High-level Programming Languages☆56Updated last year
- GPT AiCSA(Code security audit),SAST(Static Application Security Testing,静态应用程序安全测试),JAR security analysis, static vulnerability and vulne…☆57Updated 10 months ago
- Kubernetes POC for utilizing write mount to /var/log for getting a root on the host☆92Updated 4 years ago
- 🌶 一些和容器化/容器编排/服务网格等技术相关的安全代码片段[自用备份]☆80Updated 3 years ago
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party Applications☆14Updated 6 months ago
- 《深入理解DAST动态应用程序安全测试》Dynamic Application Security Testing.☆47Updated 2 years ago
- 基于JVM-Sandbox实现RASP安全监控防护☆51Updated last year
- 《深入理解Semgrep》Finding vulnerabilities with Semgrep.☆40Updated last year
- ☆24Updated 2 years ago
- Python bindings for CodeQL CLI☆49Updated 3 years ago
- awesome resources about cloud native security 🐿☆309Updated last year
- ☆21Updated last year
- ☆43Updated 4 years ago
- ☆81Updated 3 years ago
- ☆16Updated 3 years ago
- Intentionally vulnerable Go web app.☆42Updated 11 months ago
- Hades is an cross-platform HIDS with kernel-space data collection.☆44Updated last year
- A curated list of audit rules which extract from Source Code Auditing tools.☆13Updated 4 years ago
- Example of passing file descriptors into a container to perform a privilege escalation on the host☆23Updated 4 years ago
- 这个脚本主要提供对pypi供应链的源头进行安全扫描研究,扫描并发现未知的恶意包情况。☆31Updated last year
- cloud-audit (云安全审计助手)是检测公有云厂商AK/SK泄漏被利用的工具,通过定期调用云平台接口审计日志,基于异常行为/黑特征/基线发现疑似入侵行为。☆33Updated 5 months ago