drydock is a Docker security audit tool written in Python. It allows for the easy creation and use of custom audit profiles to eliminate noise and false alarms. Reports are saved in JSON format for easier parsing. drydock is based on the CIS Docker 1.6 Benchmark and heavily uses the docker-py client API for communication with Docker. To use drydock, clone the repository, install requirements, and run the tool with a provided profile or create custom profiles.
FEATURES
ALTERNATIVES
Automated script for creating a vulnerable Azure cloud lab to train offensive security skills.
Cloud security project focusing on discovering and protecting privileged entities in AWS and Azure environments.
Nuvola is a tool for security analysis on AWS environments with a focus on creating a digital twin of cloud platforms.
A tool to analyze and audit AWS environments for security issues and misconfigurations.
Discover and understand the Docker Layer 2 ICC Bug and its implications on inter-container communication.
Weave Scope automatically generates a map of your application for troubleshooting and monitoring Docker & Kubernetes.
A command-line tool to get valuable information out of AWS CloudTrail and a general purpose toolbox for working with IAM policies
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.