Seccomp-Diff
https://github.com/antitree/seccomp-diff
#container #docker #security #k8s #kubernetes
Analyze binaries and containers to extract and disassemble seccomp-bpf profiles. This tools is designed to help you determine whether or not a given seccomp-bpf profile is more or less constrained than others as well as give you the ground truth for the filters applied to a process.https://github.com/antitree/seccomp-diff
#container #docker #security #k8s #kubernetes
OSINT Toolkit
https://github.com/dev-lu/osint_toolkit
#security #osint #tool
A full stack web application that combines many tools and services for security analysts into a single tool.
https://github.com/dev-lu/osint_toolkit
#security #osint #tool
Landrum
https://github.com/Zouuup/landrun
#linux #security
Run any Linux process in a secure, unprivileged sandbox using Landlock. Think firejail, but lightweight, user-friendly, and baked into the kernel.
https://github.com/Zouuup/landrun
#linux #security
Copacetic
https://github.com/project-copacetic/copacetic
#docker #podman #container #buildkit #security
copa is a CLI tool written in Go and based on buildkit that can be used to directly patch container images without full rebuilds. copa can also patch container images using the vulnerability scanning results from popular tools like Trivy.
https://github.com/project-copacetic/copacetic
#docker #podman #container #buildkit #security
Minisign
https://github.com/jedisct1/minisign
#security #crypto #pgp #gpg #cryptography #signatures
A dead simple tool to sign files and verify digital signatures.
https://github.com/jedisct1/minisign
#security #crypto #pgp #gpg #cryptography #signatures
When Metrics Leak Secrets: Kubernetes CTF Lessons
https://programmerprodigy.code.blog/2025/09/01/when-metrics-leak-secrets-kubernetes-ctf-lessons
#k8s #kubernetes #security #grafana #victoriametrics #victorialogs
https://programmerprodigy.code.blog/2025/09/01/when-metrics-leak-secrets-kubernetes-ctf-lessons
#k8s #kubernetes #security #grafana #victoriametrics #victorialogs
ChopChop
https://github.com/michelin/ChopChop
#security #devsecops #tool
ChopChop is a CLI to help developers scanning endpoints and identifying exposition of sensitive services/files/folders
https://github.com/michelin/ChopChop
#security #devsecops #tool
httpjail
https://github.com/coder/httpjail
#network #tool #security #firewall
A cross-platform tool for monitoring and restricting HTTP/HTTPS requests from processes using network isolation and transparent proxy interception
https://github.com/coder/httpjail
#network #tool #security #firewall
Trivy Operator Dashboard
https://github.com/raoulx24/trivy-operator-dashboard
#trivy #security #k8s #kubernetes #operator
https://github.com/raoulx24/trivy-operator-dashboard
#trivy #security #k8s #kubernetes #operator
dalec
https://github.com/Azure/dalec
#linux #devops #containers #packages #security
Produce secure packages and containers with declarative configurations
https://github.com/Azure/dalec
#linux #devops #containers #packages #security
SafeLine
https://github.com/chaitin/SafeLine
#waf #security
SafeLine is a self-hosted WAF(Web Application Firewall) to protect your web apps from attacks and exploits.
https://github.com/chaitin/SafeLine
#waf #security