Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
Devsecops GitHub Repositories
Explore popular GitHub repositories tagged “devsecops”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Find secrets with Gitleaks 🔑
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Find, verify, and analyze leaked credentials
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment. Connect your agents now and build on the Agentic Cloud Defender.
Database governance built for humans and agents — controlling changes and access across every major database.
Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
🐚 Python-powered shell. Full-featured, cross-platform and AI-friendly.
Enterprise-ready zero-trust access platform built on WireGuard®.
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
Tfsec is now part of Trivy
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
Ultimate DevSecOps library
Open Source Vulnerability Management Platform
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
Open Source Cloud Native Application Protection Platform (CNAPP)
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:
ContainerSSH: Launch containers on demand
🔥Open source RASP solution
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.