Skip to content
52

Awesome Devsecops

Curating the best DevSecOps resources and tooling.

1.7k stars254 forks149 entriesLast push Aug 2, 2024 (2 years ago)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

General

DevSecOps

is an extension of the DevOps movement that aims to bring security practices into the development lifecycle through developer-centric security tooling and processes.

Resources >Articles

Our Approach to Employee Security Training

Pager Duty - Guidelines to running security training within an organisation.

DevSecOps: Making Security Central To Your DevOps Pipeline

Spacelift - An article explains what DevSecOps aims to achieve, why it’s advantageous, and how the DevSecOps lifecycle looks.

In 3 lists

Resources >Books

Alice and Bob Learn Application Security

Tanya Janca - An accessible and thorough resource for anyone seeking to incorporate, from the beginning of the System Development Life Cycle, best security practices in software development.

Resources >Communities

DevSecCon

Snyk - A community that runs conferences, a blog, a podcast and a Discord dedicated to DevSecOps.

In 2 lists

TAG Security

Cloud Native Computing Foundation - TAG Security facilitates collaboration to discover and produce resources that enable secure access, policy control, and safety for operators, administrators, developers, and end-users across the cloud native ecosystem.

Resources >Conferences

AppSec Day

OWASP - An Australian application security conference run by OWASP.

DevSecCon

Snyk - A community that runs conferences, a blog, a podcast and a Discord dedicated to DevSecOps.

In 2 lists

Resources >Newsletters

Shift Security Left

Cossack Labs - A free biweekly newsletter for security-aware developers covering application security, secure architecture, DevSecOps, cryptography, incidents, etc. that can be useful for builders and (to a lesser extent) for breakers.

In 2 lists

Resources >Podcasts

Absolute AppSec

Seth Law & Ken Johnson - Discussions about current events and specific topics related to application security.

Application Security Podcast

Security Journey - Interviews with industry experts about specific application security concepts.

BeerSecOps

Aqua Security - Breaking down the silos of Dev, Sec and Ops, discussing topics that span these subject areas.

DevSecOps Podcast Series

OWASP - Discussions with thought leaders and practitioners to integrate security into the development lifecycle.

The Secure Developer

Snyk - Discussion about security tools and best practices for software developers.

Resources >Secure Development Guidelines

Application Security Verification Standard

OWASP - A framework of security requirements and controls to help developers design and develop secure web applications.

In 2 lists

Coding Standards

CERT - A collection of secure development standards for C, C++, Java and Android development.

Fundamental Practices for Secure Software Development

SAFECode - Guidelines for implementing key secure development practices throughout the SDLC.

Proactive Controls

OWASP - OWASP's list of top ten controls that should be implemented in every software development project.

Secure Coding Guidelines

Mozilla - A guideline containing specific secure development standards for secure web application development.

In 3 lists

Secure Coding Practices Quick Reference Guide

OWASP - A checklist to verify that secure development standards have been followed.

Resources >Secure Development Lifecycle Framework

Building Security In Maturity Model (BSIMM)

Synopsys - A framework for software security created by observing and analysing data from leading software security initiatives.

In 2 lists

Secure Development Lifecycle

Microsoft - A collection of tools and practices that serve as a framework for the secure development lifecycle.

In 2 lists

Secure Software Development Framework

NIST - A framework consisting of practices, tasks and implementation examples for a secure development lifecycle.

In 2 lists

Software Assurance Maturity Model

OWASP - A framework to measure and improve the maturity of the secure development lifecycle.

In 2 lists

Resources >Toolchains

Cloud Security and DevSecOps Best Practices and Securing Web Application Technologies (SWAT) Checklist

SANS - A poster containing the Securing Web Application Technologies (SWAT) Checklist, SANS Cloud Security Curriculum, Cloud Security Top 10, Top 12 Kubernetes Threats, and Secure DevOps Toolchain.

In 2 lists

Periodic Table of DevOps Tools

XebiaLabs - A collection of DevSecOps tooling categorised by tool functionality.

Resources >Training

Application Security Education

Duo Security - Training materials created by the Duo application security team, including introductory and advanced training presentations and hands-on labs.

Cybrary

Cybrary - Subscription based online courses with dedicated categories for cybersecurity and DevSecOps.

In 3 lists

PentesterLab

PentesterLab - Hands on labs to understand and exploit simple and advanced web vulnerabilities.

In 7 listsDetails

Practical DevSecOps

Practical DevSecOps - Learn DevSecOps concepts, tools, and techniques from industry experts with practical DevSecOps using state of the art browser-based labs.

SafeStack

SafeStack - Security training for software development teams, designed to be accessible to individuals and small teams as well as larger organisations.

Secure Code Warrior

Secure Code Warrior - Gamified and hands-on secure development training with support for courses, assessments and tournaments.

SecureFlag

OWASP - Hands-on secure coding training for Developers and Build/Release Engineers.

Security Training for Engineers

Pager Duty - A presentation created and open-sourced by PagerDuty to provide security training to software engineers.

Security Training for Everyone

Pager Duty - A presentation created and open-sourced by PagerDuty to provide security training employees.

Semgrep Academy

Semgrep - Free, on-demand courses covering topics including API security, secure coding and application security.

Web Security Academy

PortSwigger - A set of materials and labs to learn and exploit common web vulnerabilities.

In 4 listsDetails

WeHackPuple

WeHackPurple - Online courses that teach application security theory and hands-on technical lessons.

Resources >Wikis

DevSecOps Hub

Snyk - Introduction to key DevSecOps concepts, processes and technologies.

SecureFlag Knowledge Base

OWASP - A repository of information about software vulnerabilities and how to prevent them.

Tools >Dependency Management

Deepfence ThreatMapper

Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

In 6 listsDetails

Dependabot

GitHub - Automatically scan GitHub repositories for vulnerabilities and create pull requests to merge in patched dependencies.

In 3 lists

Dependency-Check

OWASP - Scans dependencies for publicly disclosed vulnerabilities using CLI or build server plugins.

Dependency-Track

OWASP - Monitor the volume and severity of vulnerable dependencies across multiple projects over time.

JFrog XRay

JFrog - Security and compliance analysis for artifacts stored in JFrog Artifactory.

In 2 lists

NPM Audit

NPM - Vulnerable package auditing for node packages built into the npm CLI.

In 2 lists

Renovate

WhiteSource - Automatically monitor and update software dependencies for multiple frameworks and languages using a CLI or git repository apps.

Requires.io

Olivier Mansion & Alexis Tabary - Automated vulnerable dependency monitoring and upgrades for Python projects.

Snyk Open Source

Snyk - Automated vulnerable dependency monitoring and upgrades using Snyk's dedicated vulnerability database.

In 2 lists

Tools >Dynamic Analysis

Automatic API Attack Tool

Imperva - Perform automated security scanning against an API based on an API specification.

In 2 lists

BurpSuite Enterprise Edition

PortSwigger - BurpSuite's web application vulnerability scanner used widely by penetration testers, modified with CI/CD integration and continuous monitoring over multiple web applications.

Gauntlt

Gauntlt - A Behaviour Driven Development framework to run security scans using common security tools and test output, defined using Gherkin syntax.

Netz

Spectral - Discover internet-wide misconfigurations, using zgrab2 and others.

In 3 lists

RESTler

Microsoft - A stateful RESTful API scanner based on peer-reviewed research papers.

In 3 lists

SSL Labs Scan

SSL Labs - Automated scanning for SSL / TLS configuration issues.

Zed Attack Proxy (ZAP)

OWASP - An open-source web application vulnerability scanner, including an API for CI/CD integration.

In 4 listsDetails

Tools >Infrastructure as Code Analysis

Checkov

Bridgecrew - Scan Terraform, AWS CloudFormation and Kubernetes templates for insecure configuration.

In 7 listsDetails

KICS

Checkmarx - Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle.

In 5 listsDetails

Spectral DeepConfig

Spectral - Find misconfiguration both in infrastructure as well as apps as early as commit time.

Terrascan

Accurics - Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

In 2 lists

Cfn Nag

Stelligent - Scan AWS CloudFormation templates for insecure configuration.

In 2 lists

Clair

Red Hat - Scan App Container and Docker containers for publicly disclosed vulnerabilities.

In 6 listsDetails

Dagda

Elías Grande - Compares OS and software dependency versions installed in Docker containers with public vulnerability databases, and also performs virus scanning.

Docker-Bench-Security

Docker - The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

In 5 listsDetails

Grype

Anchore - An easy-to-integrate open source vulnerability scanning tool for container images and filesystems.

In 6 listsDetails

Hadolint

Hadolint - Checks a Dockerfile against known rules and validates inline bash code in RUN statements.

In 3 lists

Snyk Container

Snyk - Scan Docker and Kubernetes applications for security vulnerabilities during CI/CD or via continuous monitoring.

Trivy

Aqua Security - Simple and comprehensive vulnerability scanner for containers.

In 9 listsDetails

Regula

Fugue - Evaluate Terraform infrastructure-as-code for potential security misconfigurations and compliance violations prior to deployment.

In 2 lists

Terraform Compliance

terraform-compliance - A lightweight, security and compliance focused test framework against terraform to enable negative testing capability for your infrastructure-as-code.

In 2 lists

Tfsec

Liam Galvin - Scan Terraform templates for security misconfiguration and noncompliance with AWS, Azure and GCP security best practice.

Kubescape

Cloud Native Computing Foundation - An open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters.

Kube-Score

Gustav Westling - Scan Kubernetes object definitions for security and performance misconfiguration.

In 2 lists

Kubectrl Kubesec

ControlPlane - Plugin for kubesec.io to perform security risk analysis for Kubernetes resources.

Ansible-Lint

Ansible Community - Checks playbooks for practices and behaviour that could potentially be improved. As a community backed project ansible-lint supports only the last two major versions of Ansible.

Tools >Intentionally Vulnerable Applications

Bad SSL

The Chromium Project - A container running a number of webservers with poor SSL / TLS configuration. Useful for testing tooling.

In 2 lists

Cfngoat

Bridgecrew - Cloud Formation templates for creating stacks of intentionally insecure services in AWS. Ideal for testing the Cloud Formation Infrastructure as Code Analysis tools above.

In 2 lists

CI/CD Goat

Cider Security - A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

In 2 lists

Damn Vulnerable Web App

Ryan Dewhurst - A web application that provides a safe environment to understand and exploit common web vulnerabilities.

In 2 lists

Juice Shop

OWASP - A web application containing the OWASP Top 10 security vulnerabilities and more.

In 3 lists

Kubernetes Goat

Madhu Akula - Intentionally vulnerable cluster environment to learn and practice Kubernetes security.

In 3 lists

NodeGoat

OWASP - A Node.js web application that demonstrates and provides ways to address common security vulnerabilities.

In 4 lists

Pentest-Ground

Pentest-Tools.com - Pentest-Ground is a free playground with deliberately vulnerable web applications and network services.

In 4 lists

Terragoat

Bridgecrew - Terraform templates for creating stacks of intentionally insecure services in AWS, Azure and GCP. Ideal for testing the Terraform Infrastructure as Code Analysis tools above.

In 3 lists

Vulnerable Web Apps Directory

OWASP - A collection of vulnerable web applications for learning purposes.

WrongSecrets

OWASP - Vulnerable app with examples showing how to not use secrets

Tools >Monitoring

Csper

Csper - A set of Content Security Policy tools that can test policies, monitor CSP reports and provide metrics and alerts.

Streamdal

Streamdal - Embed privacy controls in your application code to detect and monitor PII as it enters and leaves your systems, preventing it from reaching unintended databases, data streams, or pipelines.

In 2 lists

Tools >Secrets Management

Ansible Vault

Ansible - Securely store secrets within Ansible pipelines.

In 2 lists

AWS Key Management Service (KMS)

Amazon AWS - Create and manage cryptographic keys in AWS.

In 2 lists

AWS Secrets Manager

Amazon AWS - Securely store retrievable application secrets in AWS.

Azure Key Vault

Microsoft Azure - Securely store secrets within Azure.

BlackBox

StackExchange - Encrypt credentials within your code repository.

In 8 listsDetails

Chef Vault

Chef - Securely store secrets within Chef.

CredStash

Fugue - Securely store secrets within AWS using KMS and DynamoDB.

In 2 lists

CyberArk Application Access Manager

CyberArk - Secrets management for applications including secret rotation and auditing.

Docker Secrets

Docker - Store and manage access to secrets within a Docker swarm.

Git Secrets

Amazon AWS - Scan git repositories for secrets committed within code or commit messages.

In 5 listsDetails

Gopass

Gopass - Password manager for teams relying on Git and gpg. Manages secrets in encrypted files and repositories.

In 4 listsDetails

Google Cloud Key Management Service (KMS)

Google Cloud Platform - Securely store secrets within GCP.

HashiCorp Vault

HashiCorp - Securely store secrets via UI, CLI or HTTP API.

In 6 listsDetails

Keyscope

Spectral - Keyscope is an open source key and secret workflow tool (validation, invalidation, etc.) built in Rust.

In 4 lists

Pinterest Knox

Pinterest - Securely store, rotate and audit secrets.

Secrets Operations (SOPS)

Mozilla - Encrypt keys stored within YAML, JSON, ENV, INI and BINARY files.

In 6 listsDetails

Teller

Spectral - A secrets management tool for developers - never leave your command line for secrets.

In 2 lists

Tools >Secrets Scanning

CredScan

Microsoft - A credential scanning tool that can be run as a task in Azure DevOps pipelines.

Detect Secrets

Yelp - An aptly named module for (surprise, surprise) detecting secrets within a code base.

In 3 lists

GitGuardian

GitGuardian - A web-based solution that scans and monitors public and private git repositories for secrets.

In 3 lists

Gitleaks

Zachary Rice - Gitleaks is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repositories.

In 5 listsDetails

Git Secrets

Amazon AWS - Scan git repositories for secrets committed within code or commit messages.

In 5 listsDetails

Nightfall

Nightfall - A web-based platform that monitors for sensitive data disclosure across several SDLC tools, including GitHub repositories.

Repo-supervisor

Auth0 - Secrets scanning tool that can run as a CLI, as a Docker container or in AWS Lambda.

In 3 lists

SpectralOps

Spectral - Automated code security, secrets, tokens and sensitive data scanning.

truffleHog

Truffle Security - Searches through git repositories for secrets, digging deep into commit history and branches.

In 5 listsDetails

Tools >Static Analysis

DevSkim

Microsoft - A set of IDE plugins, CLIs and other tools that provide security analysis for a number of programming languages.

In 5 listsDetails

Graudit

Eldar Marcussen - Grep source code for potential security flaws with custom or pre-configured regex signatures.

Hawkeye

Hawkeyesec - Modularised CLI tool for project security, vulnerability and general risk highlighting.

In 2 lists

LGTM

Semmle - Scan and monitor code for security vulnerabilities using custom or built-in CodeQL queries.

In 4 listsDetails

RIPS

RIPS Technologies - Automated static analysis for PHP, Java and Node.js projects.

In 3 lists

SemGrep

r2c - Semgrep is a fast, open-source, static analysis tool that finds bugs and enforces code standards at editor, commit, and CI time.

In 4 listsDetails

SonarLint

SonarSource - An IDE plugin that highlights potential security security issues, code quality issues and bugs.

In 2 lists

SonarQube

SonarSource - Scan code for security and quality issues with support for a wide variety of languages.

In 6 listsDetails

FlawFinder

David Wheeler - Scan C / C++ code for potential security weaknesses.

Puma Scan

Puma Security - A Visual Studio plugin to scan .NET projects for potential security flaws.

Conftest

Instrumenta - Create custom tests to scan any configuration file for security flaws.

Selefra

Selefra - An open-source policy-as-code software that provides analytics for multi-cloud and SaaS.

In 4 listsDetails

Deep Dive

Discotek.ca - Static analysis for JVM deployment units including Ear, War, Jar and APK.

Find Security Bugs

OWASP - SpotBugs plugin for security audits of Java web applications. Supports Eclipse, IntelliJ, Android Studio and SonarQube.

In 2 lists

SpotBugs

SpotBugs - Static code analysis for Java applications.

In 2 lists

ESLint

JS Foundation - Linting tool for JavaScript with multiple security linting rules available.

In 6 listsDetails

Golang Security Checker

securego - CLI tool to scan Go code for potential security flaws.

In 5 listsDetails

Security Code Scan

Security Code Scan - Static code analysis for C# and VB.NET applications.

Phan

Phan - Broad static analysis for PHP applications with some support for security scanning features.

In 2 lists

PHPCS Security Audit

Floe - PHP static analysis with rules for PHP, Drupal 7 and PHP related CVEs.

In 2 lists

Progpilot

Design Security - Static analysis for PHP source code.

In 3 lists

Bandit

Python Code Quality Authority - Find common security vulnerabilities in Python code.

In 6 listsDetails

Brakeman

Justin Collins - Static analysis tool which checks Ruby on Rails applications for security vulnerabilities.

In 6 listsDetails

DawnScanner

Paolo Perego - Security scanning for Ruby scripts and web application. Supports Ruby on Rails, Sinatra and Padrino frameworks.

Tools >Supply Chain Security

Harden Runner GitHub Action

StepSecurity - installs a security agent on the GitHub-hosted runner (Ubuntu VM) to prevent exfiltration of credentials, detect compromised dependencies and build tools, and detect tampering of source code during the build.

Overlay

SCAR - a browser extension helping developers evaluate open source packages before picking them.

In 2 lists

Preflight

Spectral - helps you verify scripts and executables to mitigate supply chain attacks in your CI and other systems, such as in the recent Codecov hack.

In 2 lists

Sigstore

sigstore is a set of free to use and open source tools, including fulcio, cosign and rekor, handling digital signing, verification and checks for provenance needed to make it safer to distribute and use open source software.

In 2 lists

Syft

Anchore - A CLI tool for generating a Software Bill of Materials (SBOM) from container images and filesystems.

In 6 listsDetails

Tools >Threat Modelling

Awesome Threat Modelling

Practical DevSecOps - A curated list of threat modelling resources.

In 3 listsDetails

SecuriCAD

Forseeti - Treat modelling and attack simulations for IT infrastructure.

In 2 lists

IriusRisk

IriusRisk - Draw threat models and capture threats and countermeasures and manage risk.

Raindance Project

DevSecOps - Use attack maps to identify attack surface and adversary strategies that may lead to compromise.

In 2 lists

SD Elements

Security Compass - Identify and rank threats, generate actionable tasks and track related tickets.

In 2 lists

Threat Dragon

OWASP - Threat model diagramming tool.

In 2 lists

Threat Modelling Tool

Microsoft - Threat model diagramming tool.

Threatspec

Threatspec - Define threat modelling as code.

In 2 lists
See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed yesterday
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
88

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k563 entriesPushed 27 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago