ASH - The Automated Security Helper Logo

ASH - The Automated Security Helper

0
Free
Visit Website

The security helper tool was created to help you reduce the probability of a security violation in a new code, infrastructure or IAM configuration by providing a fast and easy tool to conduct preliminary security check as early as possible within your development process. It is not a replacement of a human review nor standards enforced by your team/customer. It uses light, open source tools to maintain its flexibility and ability to run from anywhere. ASH is cloning and running different open-source tools, such as: git-secrets, bandit, Semgrep, Grype, Syft, nbconvert, npm-audit, checkov, cdk-nag and cfn-nag. Please review the tools LICENSE before usage. ASH change advisory: We are currently working on a re-architecture of ASH targeting a single-container architecture as well as documentation to go along with it. Supported frameworks: The security helper supports

FEATURES

ALTERNATIVES

Automatic authorization enforcement detection extension for Burp Suite

ARM TrustZone provides a secure execution environment for applications on ARM processors.

Hackazon is a free, vulnerable test site with an online storefront to train and test IT security professionals on various vulnerabilities like SQL Injection and cross-site scripting.

DOMPurify is a fast XSS sanitizer for HTML, MathML, and SVG.

DECAF++ is a fast whole-system dynamic taint analysis framework with improved performance and elasticity.

Enhance your Android experience with the AMAaaS Agent APK for better performance and improved user experience.

A command-line tool that scans NPM packages and ZIP files to detect exposed secrets and sensitive credentials in source code and configuration files.

Static code analyzer for Infrastructure as Code with 500+ security policies and support for various IaC tools and cloud platforms.