A collection of resources related to security benchmark frameworks. This collection includes resources for the CIS Amazon Web Services Foundations Benchmark 1.1, providing guidance on how to secure AWS environments. Resources include: * CIS Amazon Web Services Foundations Benchmark 1.1 * AWS Security Best Practices * AWS Security Configuration Guides * AWS Security Whitepapers This collection is designed to help security professionals and developers ensure the security of their AWS environments.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Web-application vulnerability scanner with extensive coverage of security testing modules.
A tool to run YARA rules against node_module folders to identify suspicious scripts
Open source web application security scanner with 200+ vulnerability identification capabilities.
NoSQLMap is a Python tool for auditing and automating injection attacks on NoSQL databases.
The Node.js Bug Bounty Program is a program aimed at identifying and fixing security vulnerabilities in the Node.js ecosystem.
Deliberately vulnerable web application for security professionals to practice attack techniques.
Gamma Ray is a software that helps developers to look for vulnerabilities on their Node.js applications with a pluggable infrastructure for integration with vulnerabilities databases.
A runtime threat management and attack path enumeration tool for cloud-native environments
FullHunt is a next-generation attack surface security platform that enables companies to discover, monitor, and secure their external attack surfaces.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.