drydock is a Docker security audit tool written in Python. It allows for the easy creation and use of custom audit profiles to eliminate noise and false alarms. Reports are saved in JSON format for easier parsing. drydock is based on the CIS Docker 1.6 Benchmark and heavily uses the docker-py client API for communication with Docker. To use drydock, clone the repository, install requirements, and run the tool with a provided profile or create custom profiles.
FEATURES
ALTERNATIVES
Generate Amazon GuardDuty findings related to real AWS resources with multiple tests available.
AWS Scout2 is a security tool for AWS administrators to assess their environment's security posture.
A tool to analyze and audit AWS environments for security issues and misconfigurations.
AWS serverless cloud security tool for parsing and alerting on CloudTrail logs using EQL.
CLI tool for deleting AWS resources in bulk with inspecting functionality.
ScubaGear assesses Microsoft 365 tenant configurations against CISA Secure Configuration Baselines, using PowerShell and Open Policy Agent to compare settings and generate compliance reports.
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

Kriptos
An AI-driven data classification and governance platform that automatically discovers, analyzes, and labels sensitive information while providing risk management and compliance capabilities.

System Two Security
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.

Aikido Security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.

Permiso
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.

Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.

Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.