Terrascan is a static code analyzer for Infrastructure as Code that allows you to seamlessly scan IaC for misconfigurations, monitor provisioned cloud infrastructure for changes, detect security vulnerabilities, and compliance violations. It offers flexibility to run locally or integrate with CI/CD pipelines. Key features include 500+ security best practice policies, scanning of Terraform, AWS CloudFormation, Azure Resource Manager, Kubernetes, Dockerfiles, and integration with AWS, Azure, GCP, Kubernetes, Dockerfile, and GitHub.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.
QIRA is a competitor to strace and gdb with MIT license, supporting Ubuntu and Docker for wider compatibility.
A security-focused general purpose memory allocator providing the malloc API with hardening against heap corruption vulnerabilities.
A PHP port of Rack::Honeypot, a spam trap that detects and blocks spambots
Integrates static APK analysis with Yara and requires re-compilation of Yara with the androguard module.
A comprehensive toolkit for web application security testing, offering a range of products and solutions for identifying vulnerabilities and improving security posture.
A web application security testing platform that helps you test your knowledge on web application security through realistic scenarios with known vulnerabilities.
Search engine for open-source Git repositories with advanced features like case sensitivity and regular expressions.
ConDroid performs concolic execution of Android apps to observe 'interesting' behavior in dynamic analysis.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.