IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and Kubernetes.
-
Updated
Jun 30, 2026 - Python
IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and Kubernetes.
Security-focused linter for Docker Compose files. Catches dangerous misconfigurations before they reach production. Grounded in OWASP and CIS Docker Benchmark.
Argus brings “a hundred eyes” to your project, combining leading open source security tools into a scalable, automated, continuous security pipeline.
An enterprise-grade, agentless, and open-source cloud security platform for AWS, GCP, and Azure that combines CSPM, DSPM, CIEM, ASM, and vulnerability management with deterministic YAML policies and natural language querying.
Practical, continuously verified open-source DevSecOps tools and a tested CI/CD security pipeline for GitHub Actions, covering SBOM, SAST, SCA, secrets, containers, and signing.
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Static + plan-time Terraform security analysis with attack-graph prioritisation, MITRE ATT&CK mapping, and one-click PR fix suggestions. 215 rules, 100% fix_hcl coverage.
One-command OSS AppSec scanner: SAST, SCA, secrets, IaC & SBOM for repos and container images, with cross-tool dedup and ASPM-ready reports.
A secure-by-design DevSecOps implementation integrating automated vulnerability scanning, Terraform IaC security, container hardening, and CI/CD security gates for cloud-native applications.
LLM-assisted IaC remediation for Terraform and Dockerfiles, combining Checkov and Trivy with parse validation, resource-drift protection, and verified rescans. Includes a CLI, Streamlit UI, evaluation harness, and GitHub Actions integration.
Scans Terraform and CloudFormation IaC for IAM privilege escalation risks on every pull request
Local-first Policy-as-Code with provable, deterministic remediation: AI explains the risk, a deterministic engine fixes it, and the pipeline proves 0 violations. Terraform + OPA + local LLM.
Terraform Sentinel AI is a local-first multi-agent platform that turns natural language infrastructure requests into secure, policy-aware Terraform using LangGraph, OpenRouter free-tier models, local vector retrieval, and Docker-based validation workflows.
Shift-left security gate for pull requests: secrets, dependency CVEs (OSV), and IaC/CI misconfig checks with SARIF + PR comments + a policy gate.
Production-grade DevSecOps pipeline with SAST, SCA, secret detection and IaC scanning using CodeQL, Trivy and Gitleaks. Built on GitHub Actions with AWS deployment.
An opinionated secure AWS foundation solving for credential-less CI/CD and programmatic IAM role vending. Establishes preventative guardrails (OIDC, Boundaries) and detective controls (Drift Detection).
LLM-powered IaC security reviewer — Checkov, tfsec, OPA, Snyk + Claude AI for natural language remediation
Defense-in-depth security scanner for Java projects integrating 6 industry-standard tools (Trivy, Gitleaks, Semgrep, SpotBugs, Checkov, Hadolint) into a unified Dockerized pipeline. Also comes with a standalone installer.
AI-native unified cloud governance platform — multi-cloud discovery, 6R migration planning, IaC security, FinOps, compliance audit, and executive AI chat. Built on Claude Opus 4.7. EU AI Act Annex IV ready. Zero paid SaaS dependencies.
Free security scanner for vector databases and RAG systems. Checks access exposure, drift, misconfigurations, and data leakage risks.
Add a description, image, and links to the iac-security topic page so that developers can more easily learn about it.
To associate your repository with the iac-security topic, visit your repo's landing page and select "manage topics."