Explore 26 curated tools and resources
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.
An automated code remediation tool that integrates with source control platforms to automatically fix security vulnerabilities in code through AI-driven analysis and one-click implementations.
Octoscan is a static analysis tool that scans GitHub Actions workflows for security vulnerabilities and misconfigurations.
A visual guide illustrating attack paths and techniques for exploiting vulnerabilities in GitHub Actions configurations.
StepSecurity is a platform that enhances GitHub Actions security by providing network egress control, risk discovery, action replacement, and security best practices orchestration.
A tool for identifying sensitive secrets in public GitHub repositories
A GitHub App that monitors GitHub organizations or repositories for adherence to security best practices and detects policy violations.
A tool for enumerating and attacking GitHub Actions pipelines
A community-driven public malware repository providing access to malware samples, tools, and resources for the cybersecurity community.
A powerful tool for searching and scraping data from GitHub
Open-source project for detecting security risks in cloud infrastructure accounts with support for AWS, Azure, GCP, OCI, and GitHub.
Workflows for Shuffle automation tool with structured categories and customization options.
Scumblr is a web application for periodic syncs of data sources and security analysis to streamline proactive security.
Markdown version of OWASP Testing Checklist v4 for various platforms.
A compilation of suggested tools for each component in a detection and response pipeline, with real-world examples, to design effective threat detection and response pipelines.
Repository of default playbooks and custom functions for Splunk SOAR instances with content migration to Splunk's GitHub.
A sophisticated npm attack attributed to North Korean threat actors, targeting technology firms and their employees.
A platform for version control and collaboration in software development projects.
Migrated Splunk SOAR Connectors to new GitHub organization for better organization and management.
Monitors AWS and GCP accounts for policy changes and alerts on insecure configurations, with support for OpenStack and GitHub monitoring.
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.