scanners
Vulnerability Patterns Detector for C# and VB.NET
CATS is a REST API Fuzzer and negative testing tool for OpenAPI endpoints. CATS automatically generates, runs and reports tests with minimum configuration and no coding effort. Tests are self-heali…
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …
A versatile and portable proxy for capturing, manipulating, and replaying HTTP/HTTPS traffic on the go.
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
Integrates Dependency-Check reports into SonarQube
Github action to run dependency check
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
a tool to perform static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in docker images/containers and to monitor the docker daemon and running docker conta…
OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure
Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your Kubernetes YAML and Charts. Static code analysis for Ku…
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
A Burp plugin to export findings to DefectDojo
ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.
drHEADer helps with the audit of security headers received in response to a single request or a list of requests.
A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing.
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
A vulnerability scanner for container images and filesystems
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. …
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
Open Source Cloud Native Application Protection Platform (CNAPP)
m9sweeper is a free and easy kubernetes security platform.
GitHub Action for creating software bill of materials using Syft.
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submissio…
A collection of various awesome lists for hackers, pentesters and security researchers