一个漏洞扫描工具,可用于扫描容器镜像、系统文件、Git仓库、以及配置和硬编码密钥等
CORS Misconfiguration Scanner
翻译 - CORS错误配置扫描程序
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
翻译 - Bridgecrew使用Checkov防止在Terraform,Cloudformation,Kubernetes,无服务器框架和其他基础架构代码语言的构建期间对云进行错误配置。
Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.
⚙️ ArminC's autoexec for CS2 - well documented, analysed and no misconfigurations
Find and fix 400+ types of hardcoded secrets and 70+ types of infrastructure-as-code misconfigurations.
翻译 - GitGuardian Shield:使用GitGuardian保护您的秘密
🎯 Fast CORS misconfiguration vulnerabilities scanner
Discover internet-wide misconfigurations while drinking coffee
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.
This document describes common misconfigurations of F5 Networks BigIP systems.
Local privilege escalation, or remote code execution, through Splunk Universal Forwarder (UF) misconfigurations
TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.
The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.
A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.
翻译 - 一种检测Windows操作系统中由于配置错误和缺少更新而导致的特权提升漏洞的工具。
Prevent Kubernetes misconfigurations from reaching production (again 😤 )! From code to cloud, Datree provides an E2E policy enforcement solution to run automatic checks for rule violations. See our d...
翻译 - 防止 Kubernetes 错误配置进入生产环境(再次 😤 )! Datree 是一个 CLI 工具,可确保 K8s 清单和 Helm 图表遵循最佳实践以及您组织的政策。查看我们的文档:https://hub.datree.io
Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!
BadZure orchestrates the setup of Azure AD tenants, populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack pat...
This GitHub Action runs Checkov against infrastructure-as-code, open source packages, container images, and CI/CD configurations to identify misconfigurations, vulnerabilities, and license compliance ...
a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and privilege escalations attacks, replicate the tactics and t...
翻译 - 特权升级枚举工具包(64/32),具有Web API集成的快速,智能枚举。掌握自己的发现
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to sca...