ASH - The Automated Security Helper Logo

ASH - The Automated Security Helper

0
Free
Visit Website

The security helper tool was created to help you reduce the probability of a security violation in a new code, infrastructure or IAM configuration by providing a fast and easy tool to conduct preliminary security check as early as possible within your development process. It is not a replacement of a human review nor standards enforced by your team/customer. It uses light, open source tools to maintain its flexibility and ability to run from anywhere. ASH is cloning and running different open-source tools, such as: git-secrets, bandit, Semgrep, Grype, Syft, nbconvert, npm-audit, checkov, cdk-nag and cfn-nag. Please review the tools LICENSE before usage. ASH change advisory: We are currently working on a re-architecture of ASH targeting a single-container architecture as well as documentation to go along with it. Supported frameworks: The security helper supports

FEATURES

ALTERNATIVES

An insecure web application with multiple vulnerable web service components for learning real-world web service vulnerabilities.

A comprehensive toolkit for web application security testing, offering a range of products and solutions for identifying vulnerabilities and improving security posture.

Automated framework for monitoring and tampering system API calls of native macOS, iOS, and Android apps.

A third-party Nginx module that prevents common web attacks by reading a small subset of simple rules containing 99% of known patterns involved in website vulnerabilities.

Argus-SAF is a static analysis framework for security vetting Android applications.

A web security tool that scans for vulnerabilities and known attacks.

Insider is a source code analysis tool focusing on OWASP Top 10 vulnerabilities with easy integration into DevOps pipelines.

A honeypot trap for Symfony2 forms to reduce spam submissions.