dagda
pandora
dagda | pandora | |
---|---|---|
4 | 3 | |
1,112 | 236 | |
- | 0.9% | |
0.0 | 9.3 | |
12 months ago | 5 days ago | |
Python | Python | |
Apache License 2.0 | GNU Affero General Public License v3.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
dagda
-
General Docker Troubleshooting, Best Practices & Where to Go From Here
Dagda. A tool to perform static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in Docker images/containers.
-
Open source container scanning tool to find vulnerabilities and suggest best practice improvements?
https://github.com/eliasgranderubio/dagda 1k stars, updated July 27th, 2021
-
2 Widespread Attacks on Your Containerized Environment and 7 Rules to Prevent it.
Dagda uses a static analysis approach to find viruses, malware, and fake sub-images and trojans. It is based on Red Hat Security Advisories (RHSA) libraries of existing vulnerabilities databases.
-
Am I being crypto-jacked by hackers
Furthermore, there are tools such as https://github.com/eliasgranderubio/dagda.
pandora
-
Pandora is an analysis framework to discover if a file is suspicious
It appears to hash the file locally, then look it up on a number of aggregators (or local scanner such as clamav), see: https://github.com/pandora-analysis/pandora/tree/main/pandor... for list.
You will need to be subscribed to those services that are not free and have API keys for each one.
- An analysis framework to discover if a file is suspicious with a simple UI
What are some alternatives?
clair - Vulnerability Static Analysis for Containers
yaralyzer - Visually inspect and force decode YARA and regex matches found in both binary and text data. With Colors.
Harbor - An open source trusted cloud native registry project that stores, signs, and scans content.
malware-ioc - This repository contains indicators of compromise (IOCs) of our various investigations.
anchore-engine - A service that analyzes docker images and scans for vulnerabilities
robin - RObust document image BINarization
trivy - Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
pydoxtools - Effortlessly extract information from unstructured data with this library, utilizing advanced AI techniques. Compose AI in customizable pipelines and diverse sources for your projects.
opencve - CVE Alerting Platform
vimp - Compare data from multiple vulnerability scanners to get a more complete picture of potential exposures.
ingredient-phrase-tagger - Fork of the NY Times tagger with improved testing, bugfixes
grafeas - Artifact Metadata API