Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
-
Updated
Apr 16, 2026 - HTML
DevSecOps is the practice of seamlessly integrating security practices into every phase of the software development lifecycle, from initial design through integration, testing, deployment, and delivery. It emphasizes building robust security checks directly into continuous integration and continuous delivery (CI/CD) pipelines, utilizing automated security scanning, and ensuring rigorous dependency management to mitigate vulnerabilities early.
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
Vulnerable app with examples showing how to not use secrets
A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features common vulnerabilities found in real-world applications, making it an ideal platform for security professionals, developers, and enthusiasts to learn pentesting and secure coding practices.
A curated list of awesome references collected since 2018.
Website, courses, documentation, blog and youtube video tracker.
The MITRE Security Automation Framework (SAF) Command Line Interface (CLI) brings together applications, techniques, libraries, and tools developed by MITRE and the security community to streamline security automation for systems and DevOps pipelines
AI-driven Threat modeling-as-a-Code (TaaC-AI)
A Trivy plugin that scans and outputs the results (vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more) to an interactive html file.
Subagent Verification for Claude AI Code Networks 2026
Automated Proof-of-Carrying Change Management for AIOps 2026
A centralized hub for platform engineering teams, providing resources, best practices, and automation tools. Includes IaC templates, blueprints, and operational guides to help build scalable, secure, and efficient platforms for cloud-native environments and DevSecOps workflows.
Open-source AI security verification for model artifacts, live endpoints, MCP servers, and recorded agent traces. Reproducible evidence for release decisions.
Efficient DevSecOps
Sploit -- All-in-one, AI-powered cybersecurity toolkit for web, network, and phishing tests. Modular, cross-platform, Docker-ready, with GUI & CLI. Open source by AUX-441 Team.
Внедрение и эксплуатация PT Application Inspector. Подробнее: https://habr.com/ru/company/pt/blog/557142/
🛡️ A decade of technology evolution (2013–Present): Archiving cybersecurity, Linux, AI, and DevSecOps research for the Hack-Under-Root blog.
A curated hub of DevSecOps tools to secure workflows, optimized for CI/CD and more