Otto is a hybrid cloud orchestration platform designed to provision infrastructure and deploy application workloads across diverse cloud environments using infrastructure as code. It functions as an infrastructure as code provisioner that automates the deployment of consistent resources through policy-driven workflows. The project includes a hybrid cloud service mesh for managing service discovery and secure communication between applications, as well as an identity-based access controller for managing secrets and enforcing granular access controls. It also features an infrastructure knowledg
Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc
Scanopy is a self-hosted infrastructure inventory and network discovery tool. It identifies hosts, services, and workloads across subnets to build a live model of network infrastructure, maintaining a searchable catalog of assets. The system features an interactive network topology visualizer that generates physical, logical, and application dependency diagrams. It maps the nesting chain from physical hardware and hypervisors down to virtual machines and containers, utilizing SNMP for hardware metadata and container APIs for workload discovery. The platform supports distributed network scann
Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings from multiple scanners into a single dashboard. It utilizes a relational security database to catalog hosts, services, and security flaws, enabling users to track remediation and analyze organizational risk. The platform distinguishes itself through a plugin-based system that normalizes diverse security tool outputs into a unified data model. It supports deep integration with a wide array of scanners and CLI tools, intercepting shell command output or parsing report files to ag
Cartography ist ein graphbasiertes Framework zur Infrastrukturvisualisierung und Sicherheitsanalyse. Es erfasst Daten von verschiedenen Cloud-, Identitäts- und Software-as-a-Service-Anbietern, um komplexe Beziehungen zwischen Ressourcen, Benutzern und Sicherheitsergebnissen in einer zentralen Graphdatenbank zu modellieren. Durch die Abbildung dieser Abhängigkeiten ermöglicht die Plattform Unternehmen, Transparenz über ihre Umgebung zu gewinnen und potenzielle…
Die Hauptfunktionen von lyft/cartography sind: Infrastructure Knowledge Graphs, Cross-Platform Links, Data Normalization, Graph-Based Node Models, Security Analysis Queries, Semantic Normalization, Infrastructure Dependency Visualizations, Asset Inventory Aggregators.
Open-Source-Alternativen zu lyft/cartography sind unter anderem: hashicorp/otto — Otto is a hybrid cloud orchestration platform designed to provision infrastructure and deploy application workloads… snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… scanopy/scanopy — Scanopy is a self-hosted infrastructure inventory and network discovery tool. It identifies hosts, services, and… infobyte/faraday — Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings… owasp/top10 — This project is a web application security standard and vulnerability framework. It provides a comprehensive list of… veeral-patel/how-to-secure-anything — This project is a comprehensive security suite and knowledge base focused on the engineering and construction of…