18 Repos
Tools for identifying project issues and executing contingency plans.
Distinct from Project Planning: Focuses on proactive risk mitigation and contingency planning, distinct from high-level project planning.
Explore 18 awesome GitHub repositories matching software engineering & architecture · Risk Mitigation. Refine with filters or upvote what's useful.
This project provides a framework for managing multi-agent systems, designed to automate complex software development, infrastructure, and business workflows. It functions as a multi-agent workflow orchestrator that routes tasks to domain-specific workers while maintaining state persistence and infrastructure automation. By leveraging large language models, the system decomposes high-level objectives into actionable plans, ensuring that complex operations are executed with consistency and reliability. The framework distinguishes itself through its hierarchical agent registry and policy-driven
Identifies project issues and executes contingency plans for risk mitigation.
This project is a web application security guide and developer training resource. It serves as a secure coding framework and vulnerability remediation manual, providing software engineers with the tools to identify, prioritize, and fix common security holes across different application layers. The resource utilizes a structured verification framework and security audit checklists to systematically find vulnerabilities. It features a technical reference that maps specific security flaws to step-by-step instructions for remediation, supported by vulnerability statistics to help determine which
Uses frequency and impact statistics of common vulnerabilities to determine the most urgent mitigation efforts.
This project is a comprehensive software entrepreneurship curriculum and solopreneurship business playbook designed for developers. It provides a strategic framework for building, validating, and monetizing side businesses using lean startup methodology and a systematic product development approach. The project distinguishes itself by offering specific guides for digital monetization and career anti-fragility, helping software engineers transition from employment to self-employment. It focuses on turning technical skills into scalable digital assets, paid communities, and independent software
Implements a strategy using minimum viable products to test market demand and reduce feature development risk.
BloodHound is a graph-based security analysis tool designed to map trust relationships and attack vectors within Active Directory environments. It functions as an attack path mapper and risk assessment system that uses graph theory to identify hidden relationships and paths leading to high-privilege accounts. The tool specializes in network attack surface mapping and privilege escalation pathfinding. It quantifies security risks by measuring the reliability of attack paths to critical targets, allowing for the prioritization of vulnerability elimination. The system provides capabilities for
Measures the reliability of attack paths to prioritize the elimination of critical security vulnerabilities.
reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio
Ranks security flaws based on impact and frequency to generate a risk-scored list for prioritized remediation.
Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do
Teaches the full lifecycle of identifying, assessing, prioritizing, mitigating, and monitoring vulnerabilities.
Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet
Ranks vulnerabilities based on attacker techniques to prioritize the most critical weaknesses.
Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc
Ranks identified flaws based on risk scores and severity levels to focus remediation efforts on the most critical threats.
The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies, proprietary application code, container images, and infrastructure-as-code configuration files. It also serves as a platform management tool, allowing users to configure organizations, users, SSO, and reporting from the terminal rather than the web dashboard. The CLI integrates directly into development workflows, enabling scanning within IDEs, build pipelines, and version control systems. It implements static analysis with interfile data flow analysis to find complex security f
Prioritizes vulnerabilities using risk scores, severity, and exploit maturity to focus remediation.
This project is a web application security standard and vulnerability framework. It provides a comprehensive list of the most critical security risks facing web applications, paired with technical guidance and a structured methodology for identifying and mitigating these flaws. The framework functions as a secure coding guide and a risk assessment methodology, offering a standardized approach to prioritizing vulnerabilities based on their potential impact and likelihood of exploitation. It defines architectural patterns and technical recommendations to help developers implement defense in dep
Provides a standardized methodology for ranking security flaws based on impact and frequency to prioritize mitigation.
tlroadmap ist ein Engineering-Leadership-Roadmap- und Management-Curriculum, das den Übergang vom technischen Mitarbeiter zur Führungskraft begleiten soll. Es bietet eine strukturierte Zusammenstellung von Kompetenzen und eine Wissensdatenbank für technisches Management mit Fokus auf organisatorische Ausrichtung, Personalmanagement und operative Exzellenz. Das Projekt konzentriert sich auf eine Kompetenzlandkarte für Teamleiter und Frameworks für die berufliche Entwicklung. Es skizziert die Hard- und Soft-Skills, die für das Management von Entwicklern und Produktstrategien erforderlich sind, einschließlich der Erstellung individueller Wachstumspläne und der Bewertung von Führungskompetenzen. Die Ressource deckt ein breites Spektrum an Management-Fähigkeiten ab, einschließlich Talentakquise und Optimierung des Recruiting-Funnels, Management des Mitarbeiter-Lebenszyklus vom Onboarding bis zum Austritt sowie das Design operativer Workflows. Es adressiert zudem Produktmanagement durch Roadmap-Erstellung und Backlog-Priorisierung sowie Organisationsdesign und die Ausrichtung der Unternehmenskultur. Das Projekt ist als Vue-Anwendung implementiert.
Provides a process for mitigating operational risks during departures by redistributing workloads.
Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t
Ranks discovered vulnerabilities based on verification levels to highlight high-impact results.
This project is a governance, risk, and compliance platform designed to centralize security governance, risk management, and regulatory compliance activities. It functions as a cybersecurity framework manager and a quantitative risk management system, allowing organizations to track their security posture through a centralized hub. The platform is distinguished by its ability to decouple regulatory requirements from technical security controls, enabling users to map a single implementation across multiple global frameworks to reduce audit duplication. It further differentiates itself through
Assigns specific security controls to mitigate identified risks and calculate residual risk across frameworks.
go-fastdfs is a distributed file system and object storage server designed for building private cloud storage. It provides a FastDFS compatible storage implementation that manages clusters of storage nodes to handle large-scale file uploads and downloads. The system focuses on high availability through a decentralized architecture that automatically synchronizes data and repairs failures across multiple machines without a central coordinator. It specifically supports resumable file storage via HTTP, allowing large transfers to be paused and resumed from the last successful byte to handle netw
Identifies bottlenecks and iteration risks to provide early warning notifications to stakeholders.
Dieses Projekt ist ein umfassendes Referenzhandbuch und Cheat Sheet für die Docker CLI. Es bietet eine strukturierte Sammlung von Befehlen und Dokumentationen, die Benutzern helfen, Container-Lebenszyklen zu verwalten, Images zu bauen und Registries zu handhaben. Die Dokumentation behandelt speziell die Orchestrierung von Multi-Container-Anwendungen mittels Docker Compose und die Verwaltung skalierbarer Services über mehrere Knoten hinweg mittels Docker Swarm. Sie enthält zudem detaillierte Anleitungen zur Konfiguration virtueller Netzwerke, Bridges und Ports, um die Container-Kommunikation zu steuern. Der Referenzumfang erstreckt sich auf die Verwaltung von Container-Images, einschließlich Tagging und Distribution, sowie die Ressourcenwartung zur Rückgewinnung von Speicherplatz durch das Bereinigen ungenutzter Volumes und verwaister Images. Zudem bietet sie Anleitungen zur Inspektion von Container-Metadaten und zur Performance-Überwachung. Die Inhalte werden als eine Reihe von Markdown-basierten technischen Dokumenten bereitgestellt, die als statische Dateien in einem versionskontrollierten Repository gehostet werden.
Provides a reference for ranking and prioritizing security flaws for mitigation.
Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity
Prioritizes vulnerability mitigation by combining security data with exploit prediction scores to identify urgent risks.
This project is an agentic development framework and autonomous software engineering system. It utilizes a coordinated network of specialized LLM agents to automate the full software development lifecycle, from codebase exploration and architectural planning to implementation and automated refactoring. The system is distinguished by an agentic memory system and a test-driven development orchestrator. It maintains project continuity across sessions by capturing architectural learnings and state in a persistent semantic database and enforces code quality through an automated cycle of generating
Conducts premortem evaluations to identify and mitigate potential failure points before implementing technical changes.
Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles. The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports. The system supports the import of collection files to map endpoints
Provides automated mapping of scan results against security patterns to categorize and prioritize API weaknesses.