awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
deepfence avatar

deepfence/ThreatMapper

0
View on GitHub↗
5,282 estrellas·636 forks·TypeScript·Apache-2.0·3 vistasthreatmapper.org↗

ThreatMapper

ThreatMapper es una plataforma de protección de aplicaciones nativas de la nube y escáner de seguridad de infraestructura. Funciona como un sistema de gestión de vulnerabilidades y recolector de telemetría de cargas de trabajo en la nube diseñado para monitorear cargas de trabajo y detectar riesgos de seguridad en entornos de nube y contenedores.

La plataforma se distingue por un visualizador de tráfico de red que utiliza aprendizaje automático para clasificar patrones de comunicación y un sistema de mapeo de ataques basado en grafos para identificar rutas de alto riesgo entre vulnerabilidades y dependencias de red.

Sus capacidades más amplias cubren la auditoría de cumplimiento de infraestructura en la nube frente a benchmarks de seguridad, detección de amenazas en producción para malware y secretos expuestos, y la recolección de paquetes de red y telemetría de cargas de trabajo a través de sensores distribuidos.

El despliegue de componentes de escaneo a través de entornos de nube, clústeres y máquinas virtuales se gestiona mediante herramientas de contenedores e infraestructura como código.

Features

  • Attack Path Visualizations - Maps security vulnerabilities and network dependencies into a visual graph to identify high-risk attack paths.
  • Vulnerability Detection - Identifies vulnerable software components and security misconfigurations in production workloads.
  • ML-Based Flow Classifiers - Analyzes packet headers using machine learning to categorize and identify specific network communication patterns.
  • ML-Based Classifiers - Categorizes network communication patterns by analyzing packet headers through machine learning models.
  • Cloud-Native Application Protection Platforms - Provides a unified platform combining vulnerability scanning and threat detection to protect cloud workloads.
  • Compliance Security Audits - Queries cloud provider APIs to audit infrastructure settings against industry security benchmarks.
  • Runtime Threat Detection - Identifies security threats in real-time across cloud, serverless, and container platforms.
  • Cloud Compliance Auditors - Evaluates cloud infrastructure against security benchmarks and industry standards to find configuration errors.
  • Cloud Security Posture Scanners - Audits cloud configurations and resources against compliance benchmarks to identify security misconfigurations.
  • Vulnerability Management Systems - Detects vulnerable software components and exposed secrets within production containers and file systems.
  • Network Traffic Analysis - Collects and classifies network flows across distributed hosts to understand communication patterns.
  • Network Traffic Dashboards - Visualizes network traffic flows and communication patterns between services using machine learning classification.
  • Telemetry Collection - Gathers service discovery data, telemetry, and software dependencies from production platforms using agent-based and agent-less monitoring.
  • Agent-Based Collectors - Provides lightweight distributed sensors to gather workload data and network packets across cloud environments.
  • Telemetry Collectors - Gathers service discovery data and software dependencies from distributed hosts and clusters via agent-based monitoring.
  • Azure Compliance Scanners - Evaluates Azure cloud resources against security controls and benchmarks to identify misconfigurations.
  • Distributed Security Scanning Frameworks - Deploys containerized scanning components across diverse environments to detect vulnerabilities and secrets in production.
  • Malware Scanning - Scans containers and file systems using predefined rule sets to identify known indicators of compromise.
  • Secret Scanning - Locates unprotected tokens and authentication keys within containers and file systems.
  • Pattern-Based Detection - Scans containers and file systems using pattern-matching rules to detect known indicators of malware.
  • Packet Collection Systems - Gathers network traffic data from distributed hosts, cloud environments, and clusters using lightweight tools.
  • Container Security - Runtime vulnerability scanner for Kubernetes and serverless.
  • Security and Vulnerability Scanning - Runtime vulnerability scanning for containers and serverless environments.
  • Defending - Listed in the “Defending” section of the Awesome K8s Security awesome list.
  • Application Security - Identifies vulnerabilities in running container environments.
  • Cloud Security - Runtime vulnerability and compliance scanner for cloud environments.
  • Compliance and Monitoring - Hunts and ranks vulnerabilities in production environments.
  • Container and Cluster Security - Production vulnerability scanner and attack path identification tool.
  • Dependency Management - Runtime vulnerability scanner for containers and serverless environments.
  • Security and Compliance - Runtime vulnerability scanner for containers and virtual machines.
  • Seguridad y endurecimiento - Runtime vulnerability scanner for containerized environments.
  • Testing Tools - Tool for mapping and scanning vulnerabilities in cloud-native environments.
  • Vulnerability Scanning - Scans for vulnerabilities in runtime environments.

Historial de estrellas

Gráfico del historial de estrellas de deepfence/threatmapperGráfico del historial de estrellas de deepfence/threatmapper

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Alternativas open-source a ThreatMapper

Proyectos open-source similares, clasificados según cuántas características comparten con ThreatMapper.
  • bridgecrewio/checkovAvatar de bridgecrewio

    bridgecrewio/checkov

    8,798Ver en GitHub↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Python
    Ver en GitHub↗8,798
  • aquasecurity/kube-benchAvatar de aquasecurity

    aquasecurity/kube-bench

    8,078Ver en GitHub↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    Go
    Ver en GitHub↗8,078
  • aquasecurity/trivyAvatar de aquasecurity

    aquasecurity/trivy

    36,462Ver en GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    Ver en GitHub↗36,462
  • falcosecurity/falcoAvatar de falcosecurity

    falcosecurity/falco

    8,670Ver en GitHub↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    Ver en GitHub↗8,670
Ver las 30 alternativas a ThreatMapper→

Preguntas frecuentes

¿Qué hace deepfence/threatmapper?

ThreatMapper es una plataforma de protección de aplicaciones nativas de la nube y escáner de seguridad de infraestructura. Funciona como un sistema de gestión de vulnerabilidades y recolector de telemetría de cargas de trabajo en la nube diseñado para monitorear cargas de trabajo y detectar riesgos de seguridad en entornos de nube y contenedores.

¿Cuáles son las características principales de deepfence/threatmapper?

Las características principales de deepfence/threatmapper son: Attack Path Visualizations, Vulnerability Detection, ML-Based Flow Classifiers, ML-Based Classifiers, Cloud-Native Application Protection Platforms, Compliance Security Audits, Runtime Threat Detection, Cloud Compliance Auditors.

¿Qué alternativas de código abierto existen para deepfence/threatmapper?

Las alternativas de código abierto para deepfence/threatmapper incluyen: bridgecrewio/checkov — Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as… aquasecurity/kube-bench — kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… falcosecurity/falco — Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and… aquasecurity/kube-hunter — Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native… armosec/kubescape — Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and…