awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
deepfence avatar

deepfence/ThreatMapper

0
View on GitHub↗
5,282 stars·636 forks·TypeScript·Apache-2.0·3 vuesthreatmapper.org↗

ThreatMapper

ThreatMapper est une plateforme de protection d'applications cloud-native et un scanner de sécurité d'infrastructure. Il fonctionne comme un système de gestion des vulnérabilités et un collecteur de télémétrie de charge de travail cloud conçu pour surveiller les charges de travail et détecter les risques de sécurité à travers les environnements cloud et conteneurisés.

La plateforme se distingue par un visualiseur de trafic réseau qui utilise l'apprentissage automatique pour classer les modèles de communication et un système de mappage d'attaques basé sur des graphes pour identifier les chemins à haut risque entre les vulnérabilités et les dépendances réseau.

Ses capacités plus larges couvrent l'audit de conformité de l'infrastructure cloud par rapport aux benchmarks de sécurité, la détection des menaces en production pour les logiciels malveillants et les secrets exposés, et la collecte de paquets réseau et de télémétrie de charge de travail via des capteurs distribués.

Le déploiement des composants de scan à travers les environnements cloud, les clusters et les machines virtuelles est géré via des outils de conteneurs et l'infrastructure en tant que code.

Features

  • Attack Path Visualizations - Maps security vulnerabilities and network dependencies into a visual graph to identify high-risk attack paths.
  • Vulnerability Detection - Identifies vulnerable software components and security misconfigurations in production workloads.
  • ML-Based Flow Classifiers - Analyzes packet headers using machine learning to categorize and identify specific network communication patterns.
  • ML-Based Classifiers - Categorizes network communication patterns by analyzing packet headers through machine learning models.
  • Cloud-Native Application Protection Platforms - Provides a unified platform combining vulnerability scanning and threat detection to protect cloud workloads.
  • Compliance Security Audits - Queries cloud provider APIs to audit infrastructure settings against industry security benchmarks.
  • Runtime Threat Detection - Identifies security threats in real-time across cloud, serverless, and container platforms.
  • Cloud Compliance Auditors - Evaluates cloud infrastructure against security benchmarks and industry standards to find configuration errors.
  • Cloud Security Posture Scanners - Audits cloud configurations and resources against compliance benchmarks to identify security misconfigurations.
  • Vulnerability Management Systems - Detects vulnerable software components and exposed secrets within production containers and file systems.
  • Network Traffic Analysis - Collects and classifies network flows across distributed hosts to understand communication patterns.
  • Network Traffic Dashboards - Visualizes network traffic flows and communication patterns between services using machine learning classification.
  • Telemetry Collection - Gathers service discovery data, telemetry, and software dependencies from production platforms using agent-based and agent-less monitoring.
  • Agent-Based Collectors - Provides lightweight distributed sensors to gather workload data and network packets across cloud environments.
  • Telemetry Collectors - Gathers service discovery data and software dependencies from distributed hosts and clusters via agent-based monitoring.
  • Azure Compliance Scanners - Evaluates Azure cloud resources against security controls and benchmarks to identify misconfigurations.
  • Distributed Security Scanning Frameworks - Deploys containerized scanning components across diverse environments to detect vulnerabilities and secrets in production.
  • Malware Scanning - Scans containers and file systems using predefined rule sets to identify known indicators of compromise.
  • Secret Scanning - Locates unprotected tokens and authentication keys within containers and file systems.
  • Pattern-Based Detection - Scans containers and file systems using pattern-matching rules to detect known indicators of malware.
  • Packet Collection Systems - Gathers network traffic data from distributed hosts, cloud environments, and clusters using lightweight tools.
  • Container Security - Runtime vulnerability scanner for Kubernetes and serverless.
  • Security and Vulnerability Scanning - Runtime vulnerability scanning for containers and serverless environments.
  • Defending - Listed in the “Defending” section of the Awesome K8s Security awesome list.
  • Application Security - Identifies vulnerabilities in running container environments.
  • Cloud Security - Runtime vulnerability and compliance scanner for cloud environments.
  • Compliance and Monitoring - Hunts and ranks vulnerabilities in production environments.
  • Container and Cluster Security - Production vulnerability scanner and attack path identification tool.
  • Dependency Management - Runtime vulnerability scanner for containers and serverless environments.
  • Security and Compliance - Runtime vulnerability scanner for containers and virtual machines.
  • Sécurité et durcissement - Runtime vulnerability scanner for containerized environments.
  • Testing Tools - Tool for mapping and scanning vulnerabilities in cloud-native environments.
  • Vulnerability Scanning - Scans for vulnerabilities in runtime environments.

Historique des stars

Graphique de l'historique des stars pour deepfence/threatmapperGraphique de l'historique des stars pour deepfence/threatmapper

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Start searching with AI

Alternatives open source à ThreatMapper

Projets open source similaires, classés selon le nombre de fonctionnalités partagées avec ThreatMapper.
  • bridgecrewio/checkovAvatar de bridgecrewio

    bridgecrewio/checkov

    8,798Voir sur GitHub↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Python
    Voir sur GitHub↗8,798
  • aquasecurity/kube-benchAvatar de aquasecurity

    aquasecurity/kube-bench

    8,078Voir sur GitHub↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    Go
    Voir sur GitHub↗8,078
  • aquasecurity/trivyAvatar de aquasecurity

    aquasecurity/trivy

    36,462Voir sur GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    Voir sur GitHub↗36,462
  • falcosecurity/falcoAvatar de falcosecurity

    falcosecurity/falco

    8,670Voir sur GitHub↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    Voir sur GitHub↗8,670
Voir les 30 alternatives à ThreatMapper→

Questions fréquentes

Que fait deepfence/threatmapper ?

ThreatMapper est une plateforme de protection d'applications cloud-native et un scanner de sécurité d'infrastructure. Il fonctionne comme un système de gestion des vulnérabilités et un collecteur de télémétrie de charge de travail cloud conçu pour surveiller les charges de travail et détecter les risques de sécurité à travers les environnements cloud et conteneurisés.

Quelles sont les fonctionnalités principales de deepfence/threatmapper ?

Les fonctionnalités principales de deepfence/threatmapper sont : Attack Path Visualizations, Vulnerability Detection, ML-Based Flow Classifiers, ML-Based Classifiers, Cloud-Native Application Protection Platforms, Compliance Security Audits, Runtime Threat Detection, Cloud Compliance Auditors.

Quelles sont les alternatives open-source à deepfence/threatmapper ?

Les alternatives open-source à deepfence/threatmapper incluent : bridgecrewio/checkov — Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as… aquasecurity/kube-bench — kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… falcosecurity/falco — Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and… aquasecurity/kube-hunter — Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native… armosec/kubescape — Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and…