Get the Zoom link

Security Tools & Platforms

CNAPP, CSPM, KSPM, SIEM, and other cloud security tools.

All resource categories Add a Resource
AccuKnox CNAPP preview

AccuKnox CNAPP

Zero Trust CNAPP with integrated CSPM, CWPP, KSPM, ASPM. Features runtime protection via KubeArmor with eBPF/LSM and inline mitigation.

CNAPP Open Source
Wiz CNAPP preview

Wiz CNAPP

Agentless CNAPP with security graph technology for visualizing attack paths across AWS, Azure, GCP, OCI, and Alibaba Cloud.

CNAPP Multi-Cloud
Sysdig Secure preview

Sysdig Secure

CNAPP leveraging open-source Sysdig and Falco for deep runtime threat detection with eBPF monitoring.

CNAPP Open Source
Orca Security preview

Orca Security

Agentless CNAPP with side-scanning technology and attack path analysis showing real-world exploitation scenarios.

CNAPP Agentless
Aikido Security preview

Aikido Security

Unified code-to-cloud platform combining CSPM, CWPP, SAST, SCA. Traces issues from runtime back to IaC source code.

CNAPP DevSecOps
Fidelis Security Halo preview

Fidelis Security Halo

CNAPP with patented 2MB microagent technology for Windows/Linux with self-installing capabilities.

CNAPP
Shodan preview

Shodan

Search engine for Internet-connected devices. Essential for cloud asset discovery and reconnaissance.

Recon Threat Intel
ZoomEye preview

ZoomEye

Cyberspace search engine for discovering exposed services and devices.

Recon Threat Intel
Censys preview

Censys

Internet scanning and attack surface management platform.

Recon Attack Surface
LeakIX preview

LeakIX

Search engine for exposed data and misconfigurations.

Recon Data Leaks
DNSDumpster preview

DNSDumpster

DNS reconnaissance and research tool for discovering domain assets.

Recon DNS
Security Trails preview

Security Trails

DNS and domain intelligence for attack surface discovery.

Recon DNS
grep.app preview

grep.app

Search across 500K+ GitHub repositories for code, credentials, and configurations.

Code Search Secrets
Dorksearch preview

Dorksearch

Google dork search tool for finding exposed information.

Recon OSINT
Packet Storm preview

Packet Storm

Information security news, files, and exploits database.

Research Exploits
Exploit-DB preview

Exploit-DB

Archive of public exploits and vulnerable software.

Research Exploits
CloudVulnDB preview

CloudVulnDB

Open-source database of cloud security vulnerabilities.

Research Vulnerabilities

isotope¹³ Supply-Chain Attack Compendium

Research database of supply-chain attacks from 1975 to 2026, indexed by year, vector, and payload insertion point.

Research Supply Chain
OWASP preview

OWASP

Open Web Application Security Project with cloud security resources.

Framework Research
Cloud Katana preview

Cloud Katana

Cloud adversary emulation tool for testing detection capabilities.

Red Team Azure
ScoutSuite preview

ScoutSuite

Multi-cloud security auditing tool for AWS, Azure, GCP, and more.

CSPM Multi-Cloud Open Source
ReARM Preview

ReARM

ReARM - Release-Level Supply Chain Evidence Platform. ReARM stores and manages SBOMs, xBOMs, SAST / DAST scan results, Attestations, and other Security Artifacts.

DevSecOps Vulnerability Testing Compliance Tool Open Source
Saner CNAPP preview

Saner CNAPP

CNAPP integrating CSPM, CIEM, CWPP with AI-driven monitoring and automated remediation.

CNAPP AI
Datadog Cloud Security preview

Datadog Cloud Security

Real-time threat detection with compliance automation for DevSecOps workflows.

CSPM Monitoring DevSecOps
FortiCNAPP (formerly Lacework) preview

FortiCNAPP (formerly Lacework)

AI-powered CNAPP with ML anomaly detection and automated threat response. Formerly Lacework Polygraph.

CNAPP AI CNAPP
SentinelOne Cloud preview

SentinelOne Cloud

AI-powered threat detection for cloud workloads with runtime protection.

CWPP AI CWPP
Check Point CloudGuard preview

Check Point CloudGuard

Unified security across applications, networks, and workloads with AI-driven threat prevention.

CNAPP CNAPP Enterprise
CrowdStrike Falcon Cloud preview

CrowdStrike Falcon Cloud

Identity-centric cloud security with continuous monitoring and least-privilege enforcement.

CNAPP Identity CIEM
Palo Alto Prisma Cloud preview

Palo Alto Prisma Cloud

Comprehensive CNAPP with end-to-end security from code to cloud.

CNAPP CNAPP Enterprise
Prowler preview

Prowler

Leading open-source multi-cloud security assessment tool. 500+ checks across AWS, Azure, GCP, and Kubernetes mapped to CIS, PCI-DSS, and HIPAA.

Tool Multi-Cloud Compliance Open Source
Steampipe preview

Steampipe

Query cloud APIs with SQL. 140+ plugins for AWS, Azure, GCP, Kubernetes, and SaaS - ideal for asset inventory and ad-hoc security investigations.

Tool Multi-Cloud Open Source
Checkov preview

Checkov

Open-source IaC scanner for Terraform, CloudFormation, Kubernetes, Helm, and Dockerfiles. 1,000+ built-in policies and custom Python or YAML rules.

Tool IaC DevSecOps Open Source
Trivy preview

Trivy

Aqua's all-in-one open-source scanner. CVEs, misconfigurations, secrets, and SBOMs across containers, IaC, and Kubernetes - the de facto standard for image scanning.

Tool Container Security SBOM Open Source
Kubescape preview

Kubescape

CNCF-hosted Kubernetes security platform. Scans clusters and IaC against NSA-CISA, MITRE ATT&CK, and CIS Kubernetes frameworks with remediation guidance.

Tool Kubernetes CNCF Open Source
Falco preview

Falco

CNCF graduated runtime security engine using eBPF to detect anomalous container, host, and Kubernetes activity. The reference project behind many CNAPP runtime modules.

Tool Runtime Security CNCF Open Source
CloudFox preview

CloudFox

Bishop Fox's offensive cloud enumeration CLI. Surfaces AWS and Azure attack paths, exposed services, IAM trust relationships, and secrets in user data.

Tool AWS Offensive Security Open Source
gitleaks preview

gitleaks

Fast open-source secret scanner for git history, commits, and files. Runs locally, in pre-commit hooks, or as a GitHub Action to catch credentials before they ship.

Tool Secrets Detection Open Source
Pacu preview

Pacu

Rhino Security Labs' open-source AWS exploitation framework. 80+ modules for enumeration, privilege escalation, and persistence - the standard tool for offensive cloud testing.

Tool AWS Offensive Security Open Source
Cloud Custodian preview

Cloud Custodian

Capital One's open-source policy-as-code engine for AWS, Azure, and GCP. Write YAML rules that detect and auto-remediate misconfigurations across cloud estates.

Tool Multi-Cloud Policy as Code Open Source
Stratus Red Team preview

Stratus Red Team

Datadog's open-source cloud attack emulation framework mapped to MITRE ATT&CK. Detonates safe attack scenarios across AWS, Azure, GCP, and K8s to validate detections.

Tool Multi-Cloud Detection Engineering Open Source
Cilium preview

Cilium

CNCF graduated eBPF networking and security platform for Kubernetes. Provides L3-L7 network policies, transparent encryption, and Hubble flow observability.

Tool Kubernetes Open Source
Open Policy Agent preview

Open Policy Agent (OPA)

CNCF graduated policy engine using the Rego language. Unified policy-as-code across Kubernetes admission, Terraform, Envoy, and microservice APIs.

Tool Policy as Code Kubernetes Open Source
Semgrep preview

Semgrep

Lightweight SAST tool with pattern-matching rules covering secrets, insecure SDK usage, and IaC misconfigurations. Free CLI and OSS rules; commercial tier adds a platform.

Tool DevSecOps Open Source
Kyverno preview

Kyverno

CNCF Kubernetes policy engine using YAML rules. Validates, mutates, and generates resources at admission and audits existing clusters - no dedicated policy language.

Tool Kubernetes CNCF Open Source
Sigstore preview

Sigstore

OpenSSF keyless signing for container images and SBOMs via short-lived OIDC certs and a transparency log. Adopted by Kubernetes, npm, PyPI, and major registries.

Tool Supply Chain Open Source
TruffleHog preview

TruffleHog

Open-source secret scanner that verifies leaked credentials by calling the upstream API, across git, S3, Docker, Slack, Jira, and more. Cuts false-positive triage sharply.

Tool Secrets Management DevSecOps Open Source
OpenSSF Scorecard preview

OpenSSF Scorecard

OpenSSF tool that scores repos on branch protection, signed releases, dependency hygiene, and known vulnerabilities. Used to set minimum bars on open-source dependencies.

Tool Supply Chain DevSecOps Open Source
KICS preview

KICS by Checkmarx

Open-source IaC scanner with 2,400+ queries for Terraform, CloudFormation, Kubernetes, Helm, Docker, and Ansible. Built for fast CI gates.

Tool DevSecOps Open Source
Grype preview

Grype

Open-source vulnerability scanner for container images and filesystems from Anchore. Pulls NVD, GHSA, and distro feeds; pairs with Syft for SBOMs.

Tool Supply Chain Open Source
CISA ScubaGear preview

CISA ScubaGear

ScubaGear is an assessment tool that verifies that a Microsoft 365 tenant's configuration conforms to the policies described in the SCuBA Secure Configuration Baseline documents, covering Entra ID, Exchange, Teams, SharePoint, OneDrive, Defender, and Power Platform.

Azure Tool Vulnerability Testing Cloud Scanning Compliance Free Open Source
Syft preview

Syft

Open-source SBOM generator for container images and filesystems. Outputs SPDX and CycloneDX; pairs with Grype for downstream scanning.

Tool Supply Chain SBOM Open Source
CloudQuery preview

CloudQuery

Open-source cloud asset inventory that syncs config from AWS, Azure, GCP, and Kubernetes into SQL for plain-query posture checks.

Tool Multi-Cloud CSPM Open Source
OWASP ZAP preview

OWASP ZAP

Flagship open-source DAST proxy for active scanning, fuzzing, and intercepting web app traffic. Ships with CI automation and a REST API.

Tool AppSec DAST Open Source
OSV-Scanner preview

OSV-Scanner

Google's open-source scanner backed by OSV.dev. Runs against lockfiles, SBOMs, and container images across npm, PyPI, Go, Maven, and Linux distros.

Tool SCA Open Source CI/CD
MITRE Caldera preview

MITRE Caldera

Open-source adversary emulation platform built on ATT&CK. Scripts multi-stage attack chains for detection benchmarking and purple-team exercises.

Tool Red Team Purple Team Open Source
kube-bench preview

kube-bench

Open-source CIS Kubernetes Benchmark checker from Aqua Security. Runs as a Job with specific checks for EKS, GKE, AKS, and RKE clusters.

Tool Kubernetes Compliance Open Source
Nuclei preview

Nuclei

ProjectDiscovery's fast template-driven vulnerability scanner. Thousands of YAML templates for CVEs, misconfigurations, and exposed panels - the de facto OSS scanner.

Tool Open Source DevSecOps
BloodHound Community Edition preview

BloodHound Community Edition

SpecterOps' attack-path graph for Active Directory and Entra ID. Surfaces hybrid identity chains from on-prem AD into Azure cloud roles.

Tool Active Directory Azure Open Source
CISA ScubaGoggles preview

CISA ScubaGoggles

CISA's automated assessment for Google Workspace against the SCuBA baselines - the Workspace counterpart to ScubaGear. Outputs an HTML report of findings.

Tool GCP Compliance Open Source
Tracee preview

Tracee

Aqua Security's open-source eBPF runtime security tool for Linux hosts and Kubernetes nodes. Rego-based detection with SIEM streaming.

Tool Kubernetes Runtime Security Open Source
Terrascan preview

Terrascan

Tenable's open-source IaC static analyzer covering Terraform, CloudFormation, Kubernetes, Helm, and Kustomize. Extensible via OPA/Rego.

Tool IaC DevSecOps Open Source
Wazuh preview

Wazuh

Open-source SIEM and XDR with cloud workload protection for AWS, Azure, GCP, and containers. Detection rules mapped to MITRE ATT&CK and compliance controls.

Tool SIEM Multi-Cloud Open Source
Cartography preview

Cartography

Open-source tool that maps cloud and SaaS assets into a Neo4j graph so you can query attack paths and exposure across AWS, GCP, Azure, and more.

Tool Multi-Cloud Open Source
kube-hunter preview

kube-hunter

Open-source Kubernetes penetration-testing tool that probes clusters for exposed services and misconfigurations from an attacker's perspective.

Tool Kubernetes Open Source
PMapper preview

PMapper

Open-source tool that graphs AWS IAM to identify privilege-escalation and lateral-movement paths between principals.

Tool AWS Open Source
OWASP Amass preview

OWASP Amass

Attack-surface mapping tool that enumerates subdomains and cloud-facing infrastructure from many OSINT sources.

Tool Recon Open Source
KubeLinter preview

KubeLinter

Static analysis tool that checks Kubernetes manifests and Helm charts for security and configuration best practices.

Tool Kubernetes Open Source
OWASP Dependency-Check preview

OWASP Dependency-Check

Software composition analysis tool that flags project dependencies containing known CVEs, with build-pipeline integration.

Tool DevSecOps Open Source
Cloudsplaining preview

Cloudsplaining

Scans AWS IAM policies for least-privilege violations and generates a risk-prioritized HTML report.

Tool AWS Open Source
CloudMapper preview

CloudMapper

Analyzes AWS environments to audit for misconfigurations, public exposure, and IAM issues across accounts.

Tool AWS Open Source
Clair preview

Clair

Static vulnerability scanner for container images, matching layers against known CVEs via an API for CI and registries.

Tool Supply Chain Open Source
CloudSploit preview

CloudSploit

Open-source multi-cloud CSPM that scans AWS, Azure, GCP, and Oracle accounts against hundreds of misconfiguration checks.

Tool CSPM Multi-Cloud Open Source
Tetragon preview

Tetragon

eBPF-based runtime security and observability tool from the Cilium project, with in-kernel detection and enforcement.

Tool Kubernetes Runtime Security Open Source
kubeaudit preview

kubeaudit

Command-line auditor that checks Kubernetes clusters and manifests against common workload-hardening controls.

Tool Kubernetes Open Source
HashiCorp Vault preview

HashiCorp Vault

Open-source secrets manager providing dynamic short-lived credentials, encryption as a service, and audit logging across cloud environments.

Tool Secrets Management Open Source
osquery preview

osquery

Query your endpoints and cloud hosts like a SQL database for fleet visibility, threat hunting, and misconfiguration detection.

Tool Endpoint Visibility Open Source
Polaris preview

Polaris

Open-source Kubernetes best-practice checker for security and reliability - run it as a dashboard, admission controller, or CI gate.

Tool Kubernetes Open Source
Policy Sentry preview

Policy Sentry

Open-source generator that builds least-privilege AWS IAM policies from access levels and resource ARNs, and audits existing ones.

Tool AWS IAM Open Source
Infisical preview

Infisical

Open-source, end-to-end encrypted secrets management with a CLI, native cloud integrations, versioning, and leak scanning.

Tool Secrets Management Open Source
Suricata preview

Suricata

Open-source IDS, IPS, and network security monitoring engine that inspects traffic against rulesets and scales across CPU cores.

Tool Network Security Open Source
OWASP Dependency-Track preview

OWASP Dependency-Track

OWASP flagship SBOM analysis platform that tracks component vulnerabilities across your whole application portfolio and flags newly disclosed CVEs automatically.

Tool SBOM Supply Chain Open Source
SOPS preview

SOPS

Encrypts secrets inside YAML/JSON/ENV files - values only, keys stay readable - backed by AWS KMS, GCP KMS, Azure Key Vault, age, or PGP. A GitOps secrets staple.

Tool Secrets Management Multi-Cloud Open Source
Nmap preview

Nmap

The standard network scanner for host discovery, port and service enumeration, and OS fingerprinting, extensible via the Nmap Scripting Engine.

Tool Network Security Reconnaissance Open Source
Metasploit Framework preview

Metasploit Framework

The de facto open-source exploitation and penetration-testing framework, with thousands of exploits, payloads, and post-exploitation modules.

Tool Penetration Testing Open Source
Wireshark preview

Wireshark

Industry-standard open-source packet analyzer for capturing and inspecting network traffic across hundreds of protocols.

Tool Network Security Open Source
Atomic Red Team preview

Atomic Red Team

Open-source library of ATT&CK-mapped adversary emulation tests for validating detections across endpoints and cloud.

Tool Adversary Emulation Open Source
OPA Gatekeeper preview

OPA Gatekeeper

CNCF admission controller that enforces OPA policies in Kubernetes, blocking non-compliant resources before they deploy.

Tool Kubernetes Policy as Code Open Source
Trivy Operator preview

Trivy Operator

Kubernetes operator that continuously scans running workloads for vulnerabilities, misconfigurations, and exposed secrets.

Tool Kubernetes Vulnerability Scanning Open Source
detect-secrets preview

detect-secrets

Pluggable secrets scanner for pre-commit hooks that catches credentials before they reach a repo, with a baseline for existing code.

Tool Secrets Management DevSecOps Open Source
ROADtools preview

ROADtools

Framework for enumerating and analyzing Microsoft Entra ID (Azure AD) to surface risky identity and access configurations.

Tool Azure Open Source
MicroBurst preview

MicroBurst

PowerShell toolkit for Azure security assessments covering enumeration, credential hunting, and privilege escalation.

Tool Azure Open Source
Harbor preview

Harbor

CNCF container registry with built-in vulnerability scanning, image signing, and policy controls for the software supply chain.

Tool Containers Supply Chain Open Source