Syft Logo

Syft

0
Free
Visit Website

Syft is a powerful and easy-to-use open-source tool for generating Software Bill of Materials (SBOMs) for container images and filesystems. It provides detailed visibility into the packages and dependencies in your software, helping you manage vulnerabilities, license compliance, and software supply chain security.

FEATURES

ALTERNATIVES

A cloud-native security platform that combines vulnerability management, workload protection, and security monitoring for cloud environments with context-aware threat detection capabilities.

Commercial

Zeus is a powerful tool for AWS EC2 / S3 / CloudTrail / CloudWatch / KMS best hardening practices with a focus on Identity and Access Management.

CloudScraper is a tool for enumerating cloud resources, including S3 Buckets, Azure Blobs, and Digital Ocean Storage Space.

A fully managed service that securely stores, rotates, and manages sensitive data such as database credentials and API keys.

A cloud native application protection platform that provides security monitoring and protection across cloud, on-premises, and hybrid environments.

Commercial

Kube-bench is a tool for checking Kubernetes security based on CIS Kubernetes Benchmark.

minikube implements a local Kubernetes cluster for easy application development and supports various Kubernetes features.

Collection of Kubernetes manifests creating pods with elevated privileges for security testing.

PINNED