Dagda is a tool to perform static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in docker images/containers and to monitor the docker daemon and running docker containers for detecting anomalous activities. It imports known vulnerabilities and exploits into a MongoDB and verifies software installed in docker images for vulnerabilities. It also uses ClamAV as antivirus engine for detecting trojans, viruses, malware & other malicious threats. It supports multiple Linux base images: RHEL, Ubuntu, Debian, CentOS, Fedora, and OpenSUSE. It is designed to be used by security professionals, developers, and DevOps teams to ensure the security of their docker-based applications.
FEATURES
SIMILAR TOOLS
Patch-level verification tool for bundler to check for vulnerable gems and insecure sources.
A small script to check a list of domains against open redirect vulnerability
Automated vulnerability discovery tool for Cake PHP framework with limited false positives.
A tool for detecting and exploiting Android application vulnerabilities
SSLyze is a fast and powerful SSL/TLS scanning tool and Python library with a focus on speed, reliability, and ease of integration.
Scans Alpine base images for vulnerabilities using Multi Stage builds in Docker 17.05
The Node.js Bug Bounty Program is a program aimed at identifying and fixing security vulnerabilities in the Node.js ecosystem.
Compares target's patch levels against Microsoft vulnerability database and detects missing patches.
Amass by OWASP performs comprehensive attack surface mapping and asset discovery.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.