TGViewer
false positive technologies false positive technologies @falseposotive · 211 subscribers
Post #64 733
Господа из Defecdojo представили список из опенсорс утилит для AppSec, которые они считают классными, быстрыми, полезными. Говорят нам, мол они шарят в трендах и опенсорсе, поэтому нате и смотрите.

Итак, у нас есть следующие категории: DAST, SAST, SCA, infrastructure и secrets scanning

По мне так список очевидный, и даже я бы сказал грустный (как и DefecDojo).


DAST

- ZAP - Zed Attack Proxy
- Nikto
- Arachni


SAST

- Semgrep
- Sonarqube
- Horusec

SCA

- Dependency-Track
- Trivy
- Checkov

Infrastructure

- Prowler
- OpenVAS
- Nmap

Secrets Scanning

- TruffleHog
Defectdojo Announcing the DefectDojo Open Source Security Awards DefectDojo selects the best open-source tools for DevSecOps, security automation, and scalable security, based on data from the field.
More from @falseposotive
  1. Aug 12, 2026Вот вам забавный доклад с Def Con Господа-пацаны из BCA LTD и NorthScan провели необычный…
  2. Aug 12, 2026Слайды и видосики с Def Con 34 TL;DR агенты ломают агентов, supply chain снова горит, а tr…
  3. Jun 16, 2025На конференциях BlackHat регулярно рассказывают и презентуют новые инструменты, для вопрос…
  4. May 21, 2025Привет. Я тут сделал портал https://bezrabotka.ru/, на котором собрал различные AppSec и D…
  5. Apr 16, 2025Намечаются проблемки с базами CVE и CWE от MITRE Пока мы тут спим, MITRE объявила, что её…
  6. Jan 27, 2025Тренды CWE за 10 лет Зацените как менялись тренды в CWE Top 25 Most Exploited Vulnerabilit…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →