Tools Directory

29 security tools mapped to lifecycle stages, categories and supported technologies.

TR

Trivy

Open Source

Scanner for container images, filesystems, git repositories, Kubernetes clusters and IaC templates.

Primary use Vulnerability and misconfiguration scanning

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Container SecuritySCAIaC Security
DockerKubernetesTerraformGitLab
Official website
SE

Semgrep

Open Core

Fast static analysis with pattern-based rules that resemble the source language being scanned.

Primary use Static application security testing

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Application SecuritySAST
PythonGitHubGitLab
Official website
SO

SonarQube

Open Core

Code quality and security platform with language analysers, quality gates and historical trend tracking.

Primary use Code quality and security analysis

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Application SecuritySASTCI/CD
JenkinsGitLabPython
Official website
CO

CodeQL

Open Core

Semantic code analysis engine that queries code as data, with strong dataflow and taint tracking.

Primary use Deep static analysis and variant hunting

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Application SecuritySAST
GitHubPython
Official website
OW

OWASP ZAP

Open Source

Open-source web application scanner and intercepting proxy with baseline and full active scan modes.

Primary use Dynamic application security testing

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Application SecurityDAST
DockerGitLabKubernetes
Official website
GI

Gitleaks

Open Source

Secret scanner for git history, working trees and diffs, with configurable detection rules.

Primary use Secret detection

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Application SecurityCI/CD
GitHubGitLab
Official website
TR

TruffleHog

Open Core

Secret scanner that can verify detected credentials against the issuing provider to reduce false positives.

Primary use Verified secret detection

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Application SecurityCI/CD
GitHubGitLab
Official website
CH

Checkov

Open Source

Policy-as-code scanner for Terraform, CloudFormation, Kubernetes, Helm, ARM and Dockerfiles.

Primary use Infrastructure as code scanning

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
IaCCloud Security
TerraformKubernetesAWSAzure
Official website
TF

tfsec

Open Source

Terraform-focused static analysis with fast local feedback and custom checks.

Primary use Terraform security scanning

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
IaCCloud Security
TerraformAWSAzure
Official website
KI

KICS

Open Source

Scanner for infrastructure code across Terraform, Kubernetes, Docker, Ansible and CI configuration.

Primary use Multi-format IaC scanning

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
IaCContainer Security
TerraformKubernetesAnsibleDocker
Official website
OP

Open Policy Agent

Open Source

General-purpose policy engine using Rego, usable for admission control, CI checks and application authorisation.

Primary use Policy as code

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
KubernetesIaCCloud Security
KubernetesTerraformOpenShift
Official website
KY

Kyverno

Open Source

Kubernetes-native policy engine that uses YAML policies for validation, mutation, generation and image verification.

Primary use Kubernetes admission policy

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
KubernetesContainer SecuritySupply Chain
KubernetesOpenShift
Official website
FA

Falco

Open Source

Runtime threat detection for containers and hosts, using kernel event streams and a rules engine.

Primary use Runtime security monitoring

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Container SecurityKubernetes
KubernetesLinuxOpenShift
Official website
SY

Syft

Open Source

SBOM generator for container images and filesystems, supporting SPDX and CycloneDX output.

Primary use SBOM generation

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Supply ChainSCA
DockerSPDXCycloneDX
Official website
GR

Grype

Open Source

Vulnerability scanner for container images and filesystems, pairing with Syft SBOMs.

Primary use Vulnerability scanning from SBOMs

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Container SecuritySCA
DockerCycloneDX
Official website
SI

Sigstore Cosign

Open Source

Signs and verifies container images and artefacts, including keyless signing and attestations.

Primary use Artifact signing and verification

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Supply ChainContainer Security
DockerKubernetesGitHub
Official website
HA

HashiCorp Vault

Open Core

Secrets management platform with dynamic credentials, encryption as a service and detailed audit logging.

Primary use Secrets management

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Cloud SecurityCI/CD
VaultKubernetesAWSAnsible
Official website
EX

External Secrets Operator

Open Source

Synchronises secrets from external managers into Kubernetes Secrets with scheduled refresh.

Primary use Secret synchronisation for Kubernetes

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
KubernetesCloud Security
KubernetesVaultAWS
Official website
AN

ansible-lint

Open Source

Linter for Ansible content with a production profile covering risky modules, idempotence and naming.

Primary use Ansible content quality and safety checks

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
IaCCI/CD
AnsibleAAPLinux
Official website
AN

Ansible Automation Platform

Commercial

Enterprise automation platform with RBAC, credential injection, execution environments and job auditing.

Primary use Governed infrastructure automation

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
IaCCI/CDCloud Security
AnsibleAAPRed HatLinux
Official website
PR

Prowler

Open Source

Multi-cloud security assessment tool with benchmark-aligned checks for AWS, Azure, GCP and Kubernetes.

Primary use Cloud posture assessment

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Cloud Security
AWSAzureKubernetes
Official website
CL

Cloud Custodian

Open Source

Rules engine for cloud resource governance with filters and remediation actions expressed in YAML.

Primary use Cloud policy enforcement and remediation

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Cloud SecurityIaC
AWSAzure
Official website
HA

Harbor

Open Source

Container registry with vulnerability scanning, signing, replication, quotas and RBAC per project.

Primary use Secure artefact registry

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Container SecuritySupply ChainCI/CD
DockerKubernetesOpenShift
Official website
DE

DefectDojo

Open Core

Vulnerability management platform that aggregates and deduplicates findings from many scanners.

Primary use Vulnerability aggregation and tracking

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
CI/CDApplication Security
GitLabKubernetesPython
Official website
RE

Renovate

Open Source

Automated dependency update bot with grouping, scheduling and digest pinning across ecosystems.

Primary use Dependency updates

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Supply ChainCI/CD
GitHubGitLabDocker
Official website
OP

OpenSCAP

Open Source

Compliance scanning and remediation against SCAP content such as CIS and STIG benchmarks.

Primary use Host compliance scanning

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Cloud SecurityIaC
LinuxRed HatAnsible
Official website
WA

Wazuh

Open Source

Open-source security platform combining host intrusion detection, log analysis and compliance monitoring.

Primary use SIEM and host monitoring

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Cloud SecurityContainer Security
LinuxKubernetesAWS
Official website
BU

Burp Suite

Commercial

Web security testing suite with an intercepting proxy, scanner and extensive manual testing tooling.

Primary use Manual and automated web testing

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Application SecurityDAST
LinuxPython
Official website
SN

Snyk

Commercial

Developer-oriented platform covering dependency, container, IaC and code scanning with fix advice.

Primary use Developer security platform

  1. PL
  2. CO
  3. BU
  4. TE
  5. RE
  6. DE
  7. OP
  8. MO
Application SecuritySCAContainer SecurityIaC
GitHubGitLabDockerKubernetes
Official website