Tools for identifying, prioritizing, and remediating security vulnerabilities in systems and applications.
Explore 166 curated tools and resources
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.
A cloud-native web application and API security solution that uses contextual AI to protect against known and zero-day threats without signature-based detection.
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
A wargame composed of 27 levels, with files needed in /vortex/ directory.
A vulnerability scanner that helps you identify and fix vulnerabilities in your code
Threat intelligence and digital risk protection platform
TANNER is a remote data analysis and classification service for evaluating HTTP requests and composing responses for SNARE.
FullHunt is a next-generation attack surface security platform that enables companies to discover, monitor, and secure their external attack surfaces.
A collection of Ansible roles for hardening various systems and services
Check for known vulnerabilities in your Node.js installation.
An open-source tool for finding security vulnerabilities, compliance issues, and infrastructure misconfigurations in infrastructure-as-code
Pac-resolver, a popular NPM package with 3 million weekly downloads, has a severe remote code execution flaw.
Donate to your favorite open-source projects and charities using PayPal
Patch-level verification tool for bundler to check for vulnerable gems and insecure sources.
Automate OSINT for threat intelligence and attack surface mapping with SpiderFoot.
Linux Exploit Suggester; suggests possible exploits based on the Linux operating system release number.
A series of small test cases designed to exercise different parts of a static security analyzer