Terrascan is a static code analyzer for Infrastructure as Code that allows you to seamlessly scan IaC for misconfigurations, monitor provisioned cloud infrastructure for changes, detect security vulnerabilities, and compliance violations. It offers flexibility to run locally or integrate with CI/CD pipelines. Key features include 500+ security best practice policies, scanning of Terraform, AWS CloudFormation, Azure Resource Manager, Kubernetes, Dockerfiles, and integration with AWS, Azure, GCP, Kubernetes, Dockerfile, and GitHub.
FEATURES
ALTERNATIVES
AWS Web Application Firewalls (WAFs) protect web applications and APIs from attacks, providing prebuilt security rules and the ability to create custom rules.
IronBee is an open source project building a universal web application security sensor.
OWASP Damn Vulnerable Web Sockets (DVWS) is a vulnerable web application for client-server communication with numerous vulnerabilities.
Static application security testing (SAST) tool for scanning source code against security and privacy risks.
An API security platform that discovers, documents, and tests APIs throughout the development lifecycle while maintaining a centralized catalog of all API assets.
A deliberately weak and insecure implementation of GraphQL for testing and practicing GraphQL security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.
PINNED
InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
RoboShadow
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.