Commit Graph

158 Commits

Author SHA1 Message Date
fabacab ca3e59f2c3 Add AllStar. 2021-08-14 16:07:40 -04:00
fabacab 4045e394df Add WireGuard. 2021-08-06 15:00:41 -04:00
fabacab b188d3486a Add Drool, DNS replay tool and DNS server stress test/measurement tool. 2021-08-02 15:48:12 -04:00
0xACAB 8957c44171 Merge pull request #16 from tenzir/topic/threatbus
Add Threat Bus
2021-07-04 10:06:14 -04:00
Matthias Vallentin 96c92ce6cb Add Threat Bus. 2021-06-11 15:59:11 +02:00
0xACAB 3fa021d147 Add Conftest. 2021-05-22 04:48:49 -04:00
0xACAB 592af5eecc Add Grafeas, Notary to supply chain security section. 2021-05-18 18:12:09 -04:00
fabacab 8507439733 Add see also link for Kubernetes section. 2021-05-18 10:14:13 -04:00
0xACAB 8487273304 Add "Supply chain security" section with helm-gpg tool. 2021-05-17 20:27:50 -04:00
fabacab 977fde1673 Add helm-secrets plugin. 2021-05-15 18:05:57 -04:00
fabacab 4193eb20a3 Add Teleport unified access plane. 2021-05-09 15:13:30 -04:00
fabacab 2e4bbd3227 Add Kyverno and k-rail policy enforcement tools to Kubernetes section. 2021-05-04 09:45:34 -04:00
0xACAB f5fcc4abe4 Add kubernetes-event-exporter. 2021-04-26 01:31:39 -04:00
fabacab 8732bf8815 Fix typo. 2021-04-25 23:37:05 -04:00
fabacab bc8830b0d7 Fix typo. 2021-04-11 00:06:04 -04:00
fabacab 55a49d8bf8 Link to related section. 2021-04-10 14:26:57 -04:00
fabacab 672139458d Add certificate-expiry-monitor to Kubernetes section. 2021-04-10 14:19:56 -04:00
fabacab 351c2fabb4 Generalize tracing section to monitoring, add Prometheus, Cortex. 2021-04-10 14:17:29 -04:00
0xACAB 48b09a5182 Add IPFire. 2021-04-04 11:22:33 -04:00
0xACAB bee36e7121 Add see also link. 2021-03-29 11:28:44 -04:00
fabacab 1b0ad1dae3 Add service meshes, tracing tools, sections. 2021-03-29 11:21:21 -04:00
fabacab 40caf1abdc Add GlobaLeaks, SecureDrop whistleblower submission systems. 2021-03-27 14:51:59 -04:00
0xACAB 465760cf0a Fix formatting typo. 2021-03-27 10:31:52 -04:00
0xACAB 2886281f34 Add Qubes OS. 2021-03-27 10:30:48 -04:00
fabacab 2bc46be60a Add kube-forensics. 2021-03-26 22:44:20 -04:00
fabacab 837ac32a40 Add Dangerzone malware neutering sandbox. 2021-03-16 01:26:31 -04:00
fabacab 548b2bdd5b Add ESET's Malware IOCs. 2021-03-14 14:26:03 -04:00
fabacab f47ab5a124 Add Bubblewrap sandboxing utility. 2021-03-06 11:47:15 -05:00
fabacab 741d8e9905 Add Kubernetes sub-section to "Cloud platform security" section.
Adds KubeSec, Polaris, and kube-hunter projects.
2021-02-06 08:32:17 -05:00
fabacab a70e0cb5fa Add Open Source Vulnerabilities. 2021-02-06 07:34:01 -05:00
fabacab 64014e0268 Move Bunkerized-nginx to new section, fix link for PlumHound. 2021-01-01 14:54:32 -05:00
0xACAB 57f655d213 Merge pull request #13 from bunkerity/patch-1
Add bunkerized-nginx to "Network perimeter defenses"
2021-01-01 14:44:10 -05:00
Bunkerity 37262d9688 Add bunkerized-nginx to "Network perimeter defenses"
nginx Docker image secure by default.

Avoid the hassle of following security best practices each time you need a web server or reverse proxy. Bunkerized-nginx provides generic security configs, settings and tools so you don't need to do it yourself.

Non-exhaustive list of features :
- HTTPS support with transparent Let's Encrypt automation
- State-of-the-art web security : HTTP security headers, prevent leaks, TLS hardening, ...
- Integrated ModSecurity WAF with the OWASP Core Rule Set
- Automatic ban of strange behaviors with fail2ban
- Antibot challenge through cookie, javascript, captcha or recaptcha v3
- Block TOR, proxies, bad user-agents, countries, ...
- Block known bad IP with DNSBL and CrowdSec
- Prevent bruteforce attacks with rate limiting
- Detect bad files with ClamAV
- Easy to configure with environment variables or web UI
- Automatic configuration with container labels

More info about bunkerized-nginx at https://github.com/bunkerity/bunkerized-nginx.
2021-01-01 15:29:07 +01:00
0xACAB a042fb0e4a Add Sunburst countermeasures IoC collection. 2020-12-14 02:05:07 -05:00
fabacab 1588e675e4 Add Atheris. 2020-12-12 00:39:51 -05:00
fabacab e27f60fa95 Add new subsection for signature packs. 2020-12-08 19:54:02 -05:00
fabacab e9fcf7c620 Add BadBlood. 2020-12-06 15:49:44 -05:00
fabacab 1796f969e6 Add PlumHound. 2020-12-06 15:44:56 -05:00
fabacab a14164ce30 Add Sigma and YARA to "Threat intelligence" section. 2020-12-06 15:05:06 -05:00
fabacab 127a95bbe4 Add anti-racist messaging. 2020-11-23 13:36:29 -05:00
fabacab 4649860b5e Add "See also" link to drduh's macOS Security and Privacy Guide. 2020-11-13 15:32:03 -05:00
fabacab 3228974f80 Better description for Santa. 2020-11-13 15:30:17 -05:00
fabacab 30592e81a8 Add PyREBox. 2020-10-25 19:29:48 -04:00
0xACAB 4989f25845 Merge pull request #11 from SpekBin/master
Fixing a typo
2020-10-11 16:00:49 -04:00
Peter Thaleikis 418db3fc24 Fixing a typo 2020-10-11 20:26:48 +04:00
fabacab 81406142fe Add OneFuzz, Microsoft's now open-sourced Fuzzing-as-a-Service platform. 2020-09-19 15:42:28 -04:00
fabacab cb77c0eabd Add Watchtower, a Docker container to update other Docker containers. 2020-09-16 18:24:39 -04:00
fabacab 92bb1b9694 Add Bane, an AppArmor profile generator suited to Docker containers. 2020-08-14 18:07:56 -04:00
fabacab 3b3ff44b6b Add Trivy. 2020-08-13 22:11:41 -04:00
fabacab 367c468baf Add Geneva, novel tool for improving availability of blocked content. 2020-08-12 20:57:00 -04:00