Analyse source code, bytecode or binaries for security defects before the application is built or deployed.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Application
SemgrepSonarQubeCodeQLCheckmarx
Probe a running application from the outside to find vulnerabilities that only appear at runtime.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Application
OWASP ZAPBurp SuiteNuclei
Dependency Scanning
SCA
BeginnerIdentify vulnerable, unmaintained or non-compliant third-party dependencies in your builds.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ApplicationSupply Chain
TrivyOWASP Dependency-CheckSnykGrype
Secret Detection
Secret Detection
BeginnerFind credentials, API keys and tokens committed to repositories, history, and CI configuration.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ApplicationIdentity
GitleaksTruffleHogdetect-secrets
Container Image Scanning
Container Security
BeginnerScan container images for vulnerable packages and misconfiguration, and harden how images are built.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ContainerSupply Chain
TrivyGrypeClairDocker Scout
Infrastructure as Code Security
IaC Security
IntermediateAnalyse Terraform, Kubernetes manifests, Helm charts and CloudFormation for insecure configuration before apply.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
InfrastructureCloud
CheckovtfsecKICSTerrascan
Generate and publish a machine-readable inventory of every component shipped in a release.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Supply Chain
SyftTrivycdxgen
Policy as Code
Policy as Code
AdvancedExpress security and compliance rules as versioned code and enforce them automatically in pipelines and clusters.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
GovernanceInfrastructureContainer
Open Policy AgentKyvernoConftestGatekeeper
Kubernetes Security
Kubernetes Security
AdvancedSecure clusters, workloads, RBAC, network policy, images and runtime behaviour across Kubernetes and OpenShift.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ContainerInfrastructureIdentity
FalcoKyvernoTrivyOpen Policy Agent
Secrets Management
Secrets Management
IntermediateStore, distribute, rotate and audit credentials without embedding them in code or pipeline configuration.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
IdentityCloudInfrastructure
HashiCorp VaultExternal Secrets OperatorAnsible VaultSOPS
Software Supply Chain Security
Supply Chain Security
AdvancedProtect the path from source commit to deployed artefact against tampering and dependency compromise.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Supply Chain
Sigstore CosignSyftin-totoTrivy
Artifact Signing
Artifact Signing
IntermediateCryptographically sign build outputs so consumers can verify origin and integrity.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Supply Chain
Sigstore CosignNotationGPG
Provenance
Build Provenance
AdvancedRecord verifiable metadata describing how, where and from what source an artefact was built.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Supply Chain
in-totoSigstore CosignSLSA GitHub Generator
Use the SLSA framework to measure and improve build integrity in graduated levels.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Supply ChainGovernance
SLSA GitHub Generatorin-totoSigstore Cosign
Dependency Management
Dependency Management
BeginnerKeep dependencies pinned, updated and reviewed so remediation is routine instead of an incident.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Supply ChainApplication
RenovateDependabotTrivy
Secure Coding
Secure Coding
BeginnerApply language-level and framework-level practices that eliminate whole vulnerability classes.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Application
SemgrepSonarQubeESLint
Code Review
Security Code Review
IntermediateApply targeted human review to the changes where automation is weakest: authorisation, business logic and cryptography.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Application
GitHubGitLabSemgrep
Secure Coding
Threat Modeling
IntermediateIdentify what can go wrong in a design before it is built, and record the mitigations chosen.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ApplicationGovernance
OWASP Threat DragonMiro
Pipeline Security
Pipeline Security
AdvancedHarden the CI/CD system itself: runner isolation, credential scope, pinned steps and protected branches.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
InfrastructureSupply Chain
GitHubGitLabJenkinsSigstore Cosign
Build Security
Build Security
AdvancedMake builds reproducible, isolated and free of untrusted inputs so outputs can be trusted.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Supply ChainInfrastructure
BuildKitKanikoSyft
Artifact Security
Artifact Security
IntermediateControl how build outputs are stored, promoted and retrieved from registries and artefact repositories.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Supply ChainContainer
HarborJFrog ArtifactoryTrivySigstore Cosign
Security Gates
Security Gates
IntermediateDefine objective, documented criteria that a release must meet before it can progress.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
GovernanceApplication
Open Policy AgentGitLabGitHub
Approval Controls
Approval Controls
BeginnerRequire human authorisation for high-impact changes with a clear, auditable trail.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Governance
GitHubGitLabAnsible Automation Platform
Terraform Security
Terraform Security
IntermediateSecure Terraform state, providers, modules and plan/apply workflows.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
InfrastructureCloud
CheckovtfsecTerraform CloudOPA
Ansible Security
Ansible Security
IntermediateSecure Ansible content, credentials and execution across ad-hoc runs and automation platforms.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
InfrastructureIdentity
ansible-lintAnsible VaultHashiCorp Vault
Configuration Management
Infrastructure Automation Security
AdvancedSecure automation platforms end to end: credentials, RBAC, execution environments and audit logging.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
InfrastructureIdentityGovernance
Ansible Automation PlatformHashiCorp Vaultansible-lint
Configuration Management
Configuration Management
IntermediateKeep system configuration declarative, versioned and continuously reconciled against drift.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Infrastructure
AnsibleOpenSCAPPuppet
Docker Security
Docker & Podman Security
IntermediateHarden container runtime configuration, daemon access and image build practices.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ContainerInfrastructure
Docker BenchPodmanTrivy
OpenShift Security
OpenShift Security
AdvancedApply Security Context Constraints, project isolation and integrated build security on OpenShift.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ContainerInfrastructure
OpenShiftKyvernoTrivyFalco
Runtime Security
Runtime Security
AdvancedDetect and respond to malicious behaviour in running workloads using kernel-level telemetry.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ContainerOperations
FalcoTetragonTracee
Cloud Configuration
Cloud Security
IntermediateSecure cloud accounts, identities, networks and data services across providers.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
CloudIdentityInfrastructure
ProwlerScoutSuiteCheckovCloud Custodian
Continuously assess deployed cloud configuration against benchmarks and remediate drift.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
CloudGovernance
ProwlerCloud CustodianScoutSuite
IAM
Identity & Access Management
AdvancedDesign least-privilege access for humans and workloads with short-lived, auditable credentials.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
IdentityCloudGovernance
HashiCorp VaultKeycloakAWS IAMOpen Policy Agent
Network Security
Network Security
IntermediateSegment workloads, default-deny traffic and encrypt communication in transit.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
InfrastructureCloudContainer
CiliumIstioAWS Security Groups
Workload Security
Cloud Workload Security
IntermediateProtect VMs, serverless functions and managed compute with hardening, patching and telemetry.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
CloudInfrastructureOperations
OpenSCAPFalcoCloud Custodian
Vulnerability Management
Vulnerability Management
IntermediateAggregate findings from all scanners, prioritise by real risk and drive them to closure with SLAs.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
OperationsGovernance
DefectDojoTrivyProwler
SIEM
SIEM & Security Analytics
AdvancedCentralise security-relevant events and detect suspicious activity across the estate.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Operations
Elastic SecurityWazuhSplunk
Logging
Security Logging
BeginnerCollect, structure and retain the events required for detection, investigation and audit.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
OperationsGovernance
Fluent BitLokiOpenTelemetry
Monitoring
Monitoring & Alerting
BeginnerTrack security-relevant signals and alert with enough context to act.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Operations
PrometheusGrafanaAlertmanager
Monitoring
Security Observability
IntermediateCorrelate metrics, logs and traces so security questions can be answered quickly.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Operations
OpenTelemetryGrafanaTempo
Incident Response
Incident Response
AdvancedPrepare, detect, contain, eradicate, recover and learn from security incidents.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
OperationsGovernance
PagerDutyElastic SecurityFalco
Threat Detection
Threat Detection Engineering
AdvancedWrite, test and maintain detections mapped to attacker techniques.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Operations
SigmaElastic SecurityFalco
Compliance
Continuous Compliance
IntermediateProduce control evidence automatically and continuously instead of during audit sprints.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Governance
OpenSCAPOpen Policy AgentProwler
Security Policies
Security Policies
BeginnerWrite policies and standards that are specific enough to be automated and verified.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Governance
Open Policy AgentGitHub
Risk Management
Risk Management
IntermediateRecord, prioritise and periodically review security risks with named owners and decisions.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
Governance
DefectDojoJira
Audit
Audit & Traceability
IntermediateMaintain a tamper-resistant record of who changed what, when and with what approval.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
GovernanceIdentity
Kubernetes AuditElastic SecurityGitLab
Secure Coding
API Security
IntermediateProtect APIs with strong authentication, per-object authorisation, schema validation and rate limiting.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ApplicationIdentity
OWASP ZAPSemgrepKong
Kubernetes Security
Admission Control
AdvancedValidate and mutate Kubernetes resources at creation time to enforce security requirements.
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
ContainerGovernance
KyvernoGatekeeperSigstore Cosign