Find leaked credentials at scale.
cyberstars / purpose / devsecops
Tools for devsecops
Shift-left scanning in CI/CD pipelines.
66 tools indexed
ScanSource codeCloud
Google's network vulnerability scanner.
ScanNetworksWeb apps
Vuls
—Agent-less Linux vulnerability scanner.
ScanEndpointsCloud
Catch malicious AUR packages before makepkg builds them.
ScanAnalyzeSource code
Cloud-native security and compliance from build to runtime.
ScanHardenCloudIaC
Pre-commit secret detection.
ScanSource code
LLM vulnerability scanner.
ScanFuzzWeb appsSource code
Golang security checker.
ScanAnalyzeSource code
Google's general-purpose fuzzer.
FuzzBinariesSource code
CIS benchmarks for Kubernetes.
ScanHardenCloud
Detect malicious capabilities in code, binaries and containers.
ScanAnalyzeBinariesSource code
Secure in-memory handling of secrets for Rust
HardenSource codeEndpoints
Red-team prompts, agents and RAGs.
ScanFuzzWeb appsSource code
ptai
—AI pentest tool that re-runs every exploit to verify it.
AutomateScanWeb apps
Private X.509 + SSH CA + ACME server.
HardenAutomateNetworksCloud
Terraform static analysis.
ScanHardenIaCCloud
w3af
—Web application attack and audit framework.
ScanExploitWeb apps
Embedded TLS / DTLS library.
HardenEndpointsSource code