Dev-Sec-Ops Tools
Publish Date: Jun 13, 2024
DevSecOps –Process

| Threat Modeling Tools | OWASP Threat Dragon, ThreatMode/er, Threatspec, Raindance, PyTM. MAL, Threagile. SO elements. Tutamen Threat Model Automator. Yakindu Security Analyst. Threat Playbook, DREAD,IriusRisk |
| Pre-Commit Hooks | Git Secrets, pre Commit, DetectSecrets, Git Hound. Truffle Hog |
| Software Cornposition Analysis | Rubysec, Retire IS, Requires.O, Repo-SupervSOr ,veracode |
| Static Analysis Security Testing | Bandit, Brakeman, Codesake Dawn, Findbugs, PMD, Graudit, RIPS. Puma Scan, Reshift, INSIDER CLI, Spectralops, Klocwork, HCL Appscan, Fortify, Coverity, .NET Security Guard, CodeWarrior,veracode |
| IDE Plug-ins | DevSkim, JFrog Eclipse. Snyk, CAT.net. Spotb%:s. Findbugs, FindSecBugs |
| Secrets Management | Hashicorp Torus, Keywhiz, EnvKey, Confidant, Doppler, Berglas |
| Dynamic Application Security Testing (DAST) | Arachni Scanner, Nikto. Acunetid, Fortify, Weblnspect, Veracode Dynamic Analysis, w3af, Wapiti. entnel Dynamic. Rapid7. Misterscanner, ACL Appear’, GitLab Ultimate |
| Compiance as Code | inspec, Serverspec, DevSec Hardening Framework, Kitchen O, Docker Bench for Security |
| Web Application Firewall | ModSecurity WAF, NAXSI, WebKnight, Shadow Daernon, Imperva WAF |
| Security in Infrastructure as Code | Clair. Anchore Engine, Dada. Open-sap, Dockscan, Snyk IaC Security, Infrastructure VAS, CloudSpIOit, Accurics, Checkov, TFLint |
| Vulnerability Management | ArchervSec, Defect Dojo, JackHammer, ThreadFix, Qua/ys. Flexera, Rapid7 InsightVM. Falcon Spotlight, Vulnerability Manager Plus. IP360, Kenna Security. Fsecure Elements VM, GFI Languard, Greenbone’s VM, beSECURE |
| Container scanning tools | Anchore, Snyk,Lacework,StackRox, Docker hub,Aqua Security ,Falco |
| RASP-runtime application self-protection | Fortify,Imperva, Signal Sciences,Jscrambler, Hdiv, ContrastSecurity, Appsealing, K2 Security Platform |
NOTE: The Information provided is on “as is” basis, without assurance of any kind.
Revision history
- 13-Sept-24 – first advisory released. — first list released
- 30-Sept-24- Contaoner scanning tool added
- 01-Oct-24- RASP tool list added
- 15-Jan-25 -process updated
