The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production. Automated tests are based on the CIS Docker Benchmark v1.6.0. We are making this available as an open-source utility so the Docker community can have an easy way to self-assess their hosts and Docker containers against this benchmark.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Next-generation Linux exploit suggester with improved features for finding privilege escalation vulnerabilities.
OpenVAS is an open-source vulnerability scanner that provides extensive testing capabilities for identifying security weaknesses in networks and systems.
An OSINT tool that generates username lists for companies on LinkedIn for social engineering attacks or security testing purposes.
A comprehensive database of exploits and vulnerabilities for researchers and professionals
Audits JavaScript projects for known vulnerabilities and outdated package versions using OSS Index v3 REST API.
tfsec is being replaced by Trivy, a more comprehensive open-source security solution
An automated web application security scanner that evaluates JavaScript library vulnerabilities and HTTP security headers to assess website security posture.
A free and open-source deliberately insecure web application for security enthusiasts, developers, and students to discover and prevent web vulnerabilities.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.