一个漏洞扫描工具,可用于扫描容器镜像、系统文件、Git仓库、以及配置和硬编码密钥等
Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
翻译 - 检查是否根据CIS Kubernetes基准测试中定义的安全最佳实践部署了Kubernetes
Tfsec is now part of Trivy
翻译 - 🔒🌍为您的Terraform代码提供静态分析支持的安全扫描器
Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening...
翻译 - Prowler 是一种安全工具,用于执行 AWS 安全最佳实践评估、审计、事件响应、持续监控、强化和取证准备。它包含此处列出的所有 CIS 控件 https://d0.awsstatic.com/whitepapers/compliance/AWS_CIS_Foundations_Benchmark.pdf 以及 100 多项有助于满足 GDPR、HIPAA 和其他安全要求的额外检查。
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
CloudMapper helps you analyze your Amazon Web Services (AWS) environments.
翻译 - CloudMapper可帮助您分析Amazon Web Services(AWS)环境。
Better AWS SSM Session manager CLI client
✨ Purpose only! The dangers of Bluetooth Low Energy(BLE)implementations: Unveiling zero day vulnerabilities and security flaws in modern Bluetooth LE stacks.
Coherent, zero-dependency, lazy, simple, GraphQL over WebSocket Protocol compliant server and client.
A simple SSRF-testing sheriff written in Go
翻译 - 用Go语言编写的简单的SSRF测试警长
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
翻译 - 用于AWS安全的开源工具列表:防御性,攻击性,审计,DFIR等。
Awesome XSS stuff
翻译 - 很棒的XSS东西
Btop 是一款Linux资源监控器,能监控CPU、内存、磁盘、网络和进程
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
RustRedOps is a repository for advanced Red Team techniques and offensive malware, focused on Rust 🦀
The recursive internet scanner for hackers. 🧡
An open source Bitcoin wallet password and seed recovery tool designed for the case where you already know most of your password/seed, but need assistance in trying different possible combinations.