raindance

Attack map tool

A framework to simplify attack mapping and security modeling in software development

Project intended to make Attack Maps part of software development by reducing the time it takes to complete them.

GitHub

46 stars
14 watching
24 forks
Language: GCC Machine Description
last commit: almost 10 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
devsecops/wardley-mapsA repository for mapping out strategies to advance security controls in software development47
superhedgy/attacksurfacemapperAutomates reconnaissance to identify potential attack surfaces of a target network1,324
static-flow/cloudcopyA tool that enables unauthorized access to domain controllers in the cloud by exploiting their snapshotting capabilities.120
sergiomarotco/azure-devops-server-supply-chain-attack-treeAn attack tree model for identifying potential security vulnerabilities in an Azure DevOps Server supply chain.7
indeedops/shadowbusterAn attack mapping application that visualizes real-time events and pushes them to the front end via websockets.80
reconinfosec/adversary-emulation-mapCreates an interactive visualization of an adversary emulation plan16
cybersecurityup/mitre-attack-matrixA comprehensive resource for understanding and visualizing the relationships between different types of cyber attacks and their tactics, techniques, and procedures.18
deepfence/threatmapperAn application protection platform that monitors and analyzes cloud-native applications for vulnerabilities and threats.4,861
nshalabi/attack-toolsUtilities for simulating adversary behavior in the context of threat intelligence and security analysis1,011
deepfence/yarahunterAutomated malware scanning tool for containers and filesystems using YARA ruleset1,275
step-security/github-actions-goatAn educational project demonstrating common security attacks and vulnerabilities in GitHub Actions CI/CD environments445
ramen0x3f/aggressorscriptsA collection of scripts for auditing and monitoring computer systems to detect unauthorized access272
opencybersecurityalliance/kestrel-langA language and runtime framework for building reusable, composable threat hunting workflows using Python.302
cycodelabs/ravenAnalyzes potential security vulnerabilities in Continuous Integration/Continuous Deployment workflows and repositories.634
arvanaghi/checkpleaseA collection of sandbox evasion modules written in various programming languages.904