- São Paulo, Brazil
Stars
A CLI SAST (Static application security testing) tool which was built with the intent of finding vulnerable Clojure code via rules that use a simple pattern language.
The most scalable and customizable permission server on the market. Fix your slow or broken permission system with Google's proven "Zanzibar" approach. Supports ACL, RBAC, and more. Written in Go, …
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Infection Monkey - An open-source adversary emulation platform
Open source application to instantly remediate common security issues through the use of AWS Config
🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc.
Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.
A set of tools to work with the feeds (vulnerabilities, CPE dictionary etc.) distributed by National Vulnerability Database (NVD)
How to systematically secure anything: a repository about security engineering
Interactive evaluation for Neovim (Clojure, Fennel, Scheme, Python, JavaScript, PHP, R, Lua, Rust and more!)
A curated list of resources for learning about application security
Principles to help you design and deploy a zero trust architecture
A cross-platform, OpenGL terminal emulator.
Examples and hands-on labs for Linux tracing tools workshops
open source training courses about distributed database and distributed systems
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
Learn Go with test-driven development
Master programming by recreating your favorite technologies from scratch.
Learn where some of the network sysctl variables fit into the Linux/Kernel network flow. Translations: 🇷🇺
Prevents you from committing secrets and credentials into git repositories
Kubernetes IN Docker - local clusters for testing Kubernetes
🔐💥 KeyNuker - nuke AWS keys accidentally leaked to Github
Intercept HTTP requests at the Python socket level. Fakes the whole socket module
Easy & Flexible Alerting With ElasticSearch