Policy-as-code across the stack.
Tools for cloud
AWS, GCP, Azure, Kubernetes and containers.
54 tools indexed
Evaluate IAM permissions in AWS.
Pacu
—Open-source AWS exploitation framework.
Multi-cloud security posture.
Find misconfigured object storage buckets.
Multi-cloud security auditing.
Open-source SOAR.
Local-first threat hunting over logs you already have
Open-source SCA + IaC scanner.
Build vulnerable instrumented labs.
Cloud adversary emulation.
Sigma-based threat hunting and timeline generator for cloud logs.
Syft
—Generate SBOMs from containers and source code.
Microsoft's Sysmon, on Linux.
Cross-platform O365 / AAD attack framework.
Send phishing via Microsoft Teams.
Zero-trust access for SSH, K8s and more.
Cloud-native secrets manager.
eBPF-based runtime security.
Open-source cloud-native protection platform.
Container and IaC vulnerability scanner.
Find leaked credentials at scale.
Vuls
—Agent-less Linux vulnerability scanner.
Open-source XDR and SIEM.