terrascan

Security scanner

Detects security vulnerabilities and compliance issues in infrastructure code before provisioning cloud-native infrastructure.

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

GitHub

5k stars
69 watching
504 forks
Language: Go
last commit: almost 2 years ago
Linked from 4 awesome lists

architectureawsaws-securityazure-securitycloud-securitycloudsecuritydevopsdevsecopsgcp-securityiacinfrastructureinfrastructure-as-codekubernetessastscanssecuritysecurity-toolssecurity-violationsterraformterrascan

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
aquasecurity/tfsecA tool for identifying potential misconfigurations in Terraform code during the software development process6,734
tcosolutions/betterscanA toolchain that scans source code and infrastructure IaC for security risks and provides a unified report.831
securityftw/cs-suiteAn automated tool suite to assess and improve cloud security across multiple platforms1,145
legit-labs/legitifyAutomates vulnerability detection and remediation across GitHub and GitLab assets to strengthen software security posture.782
checkmarx/kicsA tool for detecting security vulnerabilities and compliance issues in infrastructure-as-code projects2,117
bridgecrewio/checkovAn automated tool for identifying security and compliance vulnerabilities in cloud infrastructure and software packages.7,214
openscanner/xguardianA security scanner for OSX applications that detects potential vulnerabilities in URL scheme hijack, bundle ID hijack, and keychain hijack.41
deepfence/threatmapperAn application protection platform that monitors and analyzes cloud-native applications for vulnerabilities and threats.4,861
hxsecurity/terraformgoatA multi-cloud deployment tool designed to test and demonstrate the vulnerability of cloud infrastructure configurations541
praetorian-inc/snowcatAutomated tool to detect security vulnerabilities in Istio clusters by analyzing configuration and audit best practices173
secdec/attack-surface-detector-burpIdentifies web app endpoints and parameters to help detect vulnerabilities98
zupit/horusecIdentifies security flaws in software projects through static code analysis1,154
awslabs/sustainability-scannerAn open-source tool that evaluates AWS CloudFormation templates against sustainability best practices and generates reports with suggested improvements.110
boostsecurityio/poutineDetects misconfigurations and vulnerabilities in software supply chains during build pipelines.239
jupiterone/starbaseGraph-based security analysis platform337