cyberstars
cyberstars / purpose / devsecops

Tools for devsecops

Shift-left scanning in CI/CD pipelines.

75 tools indexed

Kubernetes-native policy engine.

HardenAutomateCloudIaC
GoApache-2.0

Security automation across the compliance data lifecycle.

AutomateHardenCloudEndpoints

Mobile app security testing.

ScanAnalyzeMobile apps
PythonGPL-3.0

Symbolic-execution for EVM bytecode.

ScanAnalyzeBinariesSource code
PythonMIT

Nika

Cross-file taint-analysis SAST for Java microservices

ScanAnalyzeSource codeWeb apps
PythonApache-2.0

Template-based vulnerability scanner.

ScanWeb appsNetworks
GoMIT

Adversary emulation for AI agents, LLM apps and MCP servers

ScanFuzzWeb apps
TypeScriptApache-2.0

Continuous fuzzing for open source.

FuzzAutomateSource codeBinaries
ShellApache-2.0

Dependency vulnerability scanner.

ScanSource codeCloud
GoApache-2.0

Open-source threat modeling.

AnalyzeHardenSource codeCloud
JavaScriptApache-2.0

Open-source web app scanner.

ScanInterceptWeb apps
JavaApache-2.0

Policy-as-code across the stack.

HardenAutomateCloudIaC
GoApache-2.0

File-based agent workspace for source-guided whitebox security review

AnalyzeScanSource codeWeb apps
PythonMIT

Open-source AI agent firewall for MCP and agent egress.

InterceptMonitorWeb appsNetworks
GoApache-2.0

Multi-cloud security posture.

ScanHardenCloud
PythonApache-2.0

QARK

Quick Android Review Kit.

ScanAnalyzeMobile apps
PythonApache-2.0

Detect vulnerable JS libraries.

ScanWeb appsSource code
JavaScriptApache-2.0

Self-hosted open-source WAF.

MonitorHardenWeb apps
GoApache-2.0

API fuzzer from OpenAPI/GraphQL.

FuzzScanWeb apps
PythonMIT

Lightweight static analysis.

ScanAnalyzeSource code
OCamlLGPL-2.1

Solidity / Vyper static analyzer.

ScanAnalyzeSource code
PythonAGPL-3.0

CI/CD red team framework — like Metasploit for pipelines

ExploitAutomateIaCSource code
GoAGPL-3.0

Open-source SCA + IaC scanner.

ScanAnalyzeSource codeCloud
TypeScriptApache-2.0

Solidity inspector.

AnalyzeSource code
JavaScriptApache-2.0