checkov
Vulnerability scanner
An automated tool for identifying security and compliance vulnerabilities in cloud infrastructure and software packages.
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
7k stars
59 watching
1k forks
Language: Python
last commit: 11 months ago
Linked from 7 awesome lists
awsaws-securityazurecloudformationcompliancedevopsgcphacktoberfestinfrastructure-as-codekubernetesscansstatic-analysisterraform
Related projects:
| Repository | Description | Stars |
|---|---|---|
| | A tool for detecting security vulnerabilities and compliance issues in infrastructure-as-code projects | 2,117 |
| | A training project that demonstrates how common configuration errors can be introduced into cloud infrastructure to test secure development best practices | 1,159 |
| | Checks AWS accounts for subdomain hijacking vulnerabilities | 84 |
| | A Python-based web application scanner that gathers OSINT and fuzz data to identify OWASP vulnerabilities on target websites. | 1,545 |
| | Detects security vulnerabilities and compliance issues in infrastructure code before provisioning cloud-native infrastructure. | 4,779 |
| | Detects known security vulnerabilities in Python dependencies and provides recommendations for remediation. | 1,758 |
| | A training project demonstrating how common configuration errors can lead to production cloud environment issues | 92 |
| | An automotive security exploration tool that collects and analyzes information on CAN bus services and vulnerabilities. | 753 |
| | A tool for identifying potential vulnerability points in Linux systems | 1,590 |
| | A tool for detecting vulnerabilities in web applications | 113 |
| | An account security scanner that detects vulnerabilities in online accounts by hashing credentials and checking against data breaches. | 157 |
| | Tools to identify and remove critical risks in cloud infrastructure accounts by analyzing metadata from APIs of various cloud services | 1,617 |
| | A tool to identify vulnerabilities in web applications by probing for Open Redirections and other types of attacks. | 758 |
| | Analyzes C/C++ source code for security vulnerabilities and reports potential flaws. | 498 |
| | Demonstrates how common configuration errors can lead to production cloud misconfigurations | 44 |