LunaTrace Logo

LunaTrace

0
Free
Visit Website

LunaTrace is an Open Source supply chain security and auditing tool. At its heart is a web console the tracks your projects and their dependencies, looking for vulnerabilities and other issues. This console is provided as a SAAS (available here for free) or you can deploy it and manage it yourself. Please see our LunaTrace documentation for more information. We're a team of Security Engineers on a mission to make awesome Open Source Application Security tooling. It all lives in this monorepo and here's a breakdown of where everything we've built lives. LunaTrace: A free alternative to services like GitHub Dependabot or Snyk that automatically monitors for your dependencies for vulnerabilities. It automatically integrates with GitHub Pull Requests to notify you of new CVEs before you deploy to production. Try it out in one-click via our GitHub App. Status: Production ready and under active development (our primary focus). Log4Shell CLI: A small command line utility to scan for Log4Shell. Also supports patching JAR files against Log4Shell, scanning running processes on your system, and more. Follow our Mitigation Guide for more context.

FEATURES

ALTERNATIVES

A disclosure of a bug found in Twitter's Vine and the process of procuring the source code.

A virtual host scanner with the ability to detect catch-all scenarios, aliases, and dynamic default pages, presented at SecTalks BNE in September 2017.

Open source web application security scanner with 200+ vulnerability identification capabilities.

All-in-one vulnerability intelligence platform for prioritizing remediation efforts and driving security strategies.

An automated web application security scanner that evaluates JavaScript library vulnerabilities and HTTP security headers to assess website security posture.

A tool to capture all the git secrets by leveraging multiple open source git searching tools.

An OSINT tool that generates username lists for companies on LinkedIn for social engineering attacks or security testing purposes.

A tool that checks for hijackable packages in NPM and Python Pypi registries