22 tools and resources
StepSecurity is a platform that enhances GitHub Actions security by providing network egress control, risk discovery, action replacement, and security best practices orchestration.
Monitor GitHub for sensitive data
A reconnaissance tool for GitHub organizations
Monitors GitHub for leaked secrets
A tool for identifying sensitive secrets in public GitHub repositories
A GitHub App that monitors GitHub organizations or repositories for adherence to security best practices and detects policy violations.
A tool for enumerating and attacking GitHub Actions pipelines
A community-driven public malware repository providing access to malware samples, tools, and resources for the cybersecurity community.
A powerful tool for searching and scraping data from GitHub
Open-source project for detecting security risks in cloud infrastructure accounts with support for AWS, Azure, GCP, OCI, and GitHub.
Workflows for Shuffle automation tool with structured categories and customization options.
Scumblr is a web application for periodic syncs of data sources and security analysis to streamline proactive security.
A collection of tools to perform searches on GitHub.
Markdown version of OWASP Testing Checklist v4 for various platforms.
A compilation of suggested tools for each component in a detection and response pipeline, with real-world examples, to design effective threat detection and response pipelines.
A collection of CTF write-ups using pwntools
Repository of default playbooks and custom functions for Splunk SOAR instances with content migration to Splunk's GitHub.
A sophisticated npm attack attributed to North Korean threat actors, targeting technology firms and their employees.
A tool for detecting secrets in your code
A platform for version control and collaboration in software development projects.
Migrated Splunk SOAR Connectors to new GitHub organization for better organization and management.
Monitors AWS and GCP accounts for policy changes and alerts on insecure configurations, with support for OpenStack and GitHub monitoring.