Skip to content

Entry

Deepfence ThreatMapper

Appears in 6 awesome lists

Vulnerability Scanner and Risk Evaluation for containers, serverless and hosts at runtime. ThreatMapper generates runtime BOMs from dependencies and operating system packages, matches against multiple threat feeds, scans for unprotected secrets, and scores issues based on severity and…

Open github.comdeepfence/threatmapper

Found in these lists

ciandcd

Section: secure tools · Powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

ActiveScore 69

Awesome Devsecops

Section: Dependency Management · Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

StaleScore 52

Awesome Docker

Section: Security · Powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

FreshScore 92

awesome-kubernetes-security

Section: Open Source Projects · Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless

StaleScore 45

Awesome Security

Section: Scanning / Pentesting · Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

SlowScore 70

Static Analysis

Section: Multiple languages · Vulnerability Scanner and Risk Evaluation for containers, serverless and hosts at runtime. ThreatMapper generates runtime BOMs from dependencies and operating system packages, matches against multiple threat feeds, scans for unprotected secrets, and scores issues based on severity and…

FreshScore 91

Checkov

Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.

In 7 listsDetails

docker-bench-security

script that checks for dozens of common best-practices around deploying Docker containers in production, inspired by the CIS Docker Community Edition Benchmark v1.1.0.

In 5 listsDetails

KICS

Scans IaC projects for security vulnerabilities, compliance issues, and infrastructure misconfiguration. Currently working with Terraform projects, Kubernetes manifests, Dockerfiles, AWS CloudFormation Templates, and Ansible playbooks.

In 5 listsDetails

falco

Sysdig Falco is an open source container security monitor. It can monitor application, container, host, and network activity and alert on unauthorized activity.

In 4 listsDetails

Den

Self-hosted sandbox runtime for AI agents with isolated Docker containers, cgroup v2 memory management, and dynamic pressure monitoring.

In 3 lists

segspec

Extracts network dependencies from Docker Compose, Kubernetes manifests, Helm charts, and other config files to generate Kubernetes NetworkPolicies with evidence tracing.

In 2 lists

Dependabot

GitHub - Automatically scan GitHub repositories for vulnerabilities and create pull requests to merge in patched dependencies.

In 3 lists

JFrog Xray

JFrog - Security and compliance analysis for artifacts stored in JFrog Artifactory.

In 2 lists