trufflesecurity / how-to-rotate
An open-source collection of API key rotation tutorials.
☆60Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for how-to-rotate
- ☆107Updated last month
- HashiCorp-relevant rules for the Semgrep code analysis tool☆37Updated last year
- A tool to uncover undocumented APIs from the AWS Console.☆83Updated this week
- Tool for obfuscating and deobfuscating data.☆64Updated 8 months ago
- A full insecure kubernetes application for testing security tools☆54Updated this week
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆79Updated this week
- AWS honey token manager☆84Updated 3 months ago
- ☆153Updated 2 months ago
- The security workflow engine!☆73Updated this week
- https://breaches.cloud☆36Updated last month
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆59Updated 8 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆57Updated last year
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments☆107Updated 2 months ago
- Clean accounts over permissions in GCP infra at scale☆71Updated last year
- Independently deploy customized honeyservices in AWS to trigger alerts on unauthorized access. It utilizes a dedicated CloudTrail for pre…☆44Updated this week
- boostsecurityio/lotp☆101Updated 7 months ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆79Updated 2 years ago
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆30Updated last month
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆87Updated last week
- ☆67Updated 8 months ago
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.☆35Updated 5 months ago
- Validate the isolation posture of your container environment.☆152Updated this week
- A tool to check the security settings of Github Organizations.☆69Updated last year
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.☆36Updated 10 months ago
- Vulnerable by Design AWS Cloud Development Kit (CDK) Infrastructure☆46Updated 10 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆33Updated last month
- An SBOM query language and associated utilities☆54Updated 9 months ago
- boostsecurityio/poutine☆232Updated this week
- Generate datasets of cloud audit logs for common attacks☆184Updated 3 months ago
- This application was built to help reduce the amount of time it takes to review AWS Lambda code.☆60Updated last week