devsecops
github.com/sottlmarek/devsecops ↗Ultimate DevSecOps library
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me aws resources from devsecops"
Installation instructions →What's inside
AWS
- AirIAM
IAM Least Privilege anmalyzer and Terraformer
- AWS Compliance
Check compliance of AWS configurations to security best practices.
- AWS Firewall factory
Deploy, update, and stage your WAFs while managing them centrally via FMS
- aws-iam-authenticator
A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster
- AWS Insights
Visualize AWS inventory and permissions through relationship graphs.
- aws-inventory
Helps to discover all AWS resources created in an account
DAST
Containers
- Anchore
Centralized service for inspection, analysis, and certification of container images
- Clair
Docker vulnerability scanner
- Copacetic
CLI tool for directly patching container images
- Cosign
Container signing
- Deepfence ThreatMapper
Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
- Docker bench
Docker benchmarking against CIS
Infrastructure as code security
- Ansible Security Scanner
Static security scanner for Ansible playbooks, roles, and collections; outputs SARIF, CycloneDX SBOM, and GitLab SAST.
- cfn_nag
Looks for insecure patterns in CloudFormation
- Checkov
Checkov is a static code analysis tool for infrastructure-as-code
- KICS
Checkmarx security testing opensource for IaC
- Sysdig IaC scanner action
Scans your repository with Sysdig IAC Scanner and report the vulnerabilities.
- Terraform Compliance for AWS
Check compliance of Terraform configurations to AWS security best practices.
Secrets management
- Ansible vault
Encryption/decryption utility for Ansible data files
- AWS secrets manager GH action
AWS secrets manager docs
- aws-vault
AWS Vault is a tool to securely store and access AWS credentials in a development environment
- Chef vault
allows you to encrypt a Chef Data Bag Item
- GitLeaks
Gitleaks is a scanning tool for detecting hardcoded secrets
- GitRob
Gitrob is a tool to help find potentially sensitive files pushed to public repositories on Github
Orchestration
- Automated Security Helper (ASH)
ASH is a one stop shop for security scanners, and does not require any installation. It will identify the different frameworks, and download the relevant, up to date tools. ASH is running on isolated Docker containers, keeping the user environment clean, with a single aggregated report. The following frameworks are supported: Git, Python, Javascript, Cloudformation, Terraform and Jupyter Notebooks.
- Camunda
Workflow and process automation
- DefectDojo
Security orchestration and vulnerability management platform
- Faraday
Security suite for Security Orchestration, vulnerability management and centralized information
- https://aws.amazon.com/blogs/devops/building-an-end-to-end-kubernetes-based-devsecops-software-factory-on-aws/
- https://aws.amazon.com/blogs/devops/building-end-to-end-aws-devsecops-ci-cd-pipeline-with-open-source-sca-sast-and-dast-tools/
Chaos engineering
- AWS FIS samples
AWS Fault injection simulator samples
- Chaos Engine
The Chaos Engine is a tool that is designed to intermittently destroy or degrade application resources running in cloud based infrastructure. These events are designed to occur while the appropriate resources are available to resolve the issue if the platform fails to do so on it's own.
- chaoskube
Test how your system behaves under arbitrary pod failures.
- chaos-mesh
It is a cloud-native Chaos Engineering platform that orchestrates chaos on Kubernetes environments
- Chaos monkey
Chaos Monkey is responsible for randomly terminating instances in production to ensure that engineers implement their services to be resilient to instance failures.
- CloudNuke
CLI tool to delete all resources in an AWS account
Microsoft Azure
- Azure Compliance
Check compliance of Azure configurations to security best practices.
- Azure Insights
Visualize Azure inventory and permissions through relationship graphs.
- PSRule.Rules.Azure
Check ARM, Bicep or Live Azure Tenant for security configuration best practices
- PSRule.Rules.AzureDevOps
Check Azure DevOps project for security configuration best practices
Showing a sample of 211 resources. View the full list on GitHub →