Tenable Open Source
We’re on a mission to empower everyone to secure their cloud environment. With intuitive open source tooling, the cloud native community can work together to isolate and eradicate cloud exposures, ultimately creating a more secure cloud environment for all.
Join the Tenable open source community
Whether you're a seasoned DevSecOps pro or just starting your security career, there’s a place for you to contribute to Tenable Open Source projects. Find us on GitHub here and get started today.
Share best practices, open source contributions or tips and tricks of the trade while rallying around the common goal of holistic cloud security.
Shift security into the application development lifecycle and further cyber security education with easy-to-use tooling.
Tenable open source community projects
Uniting security professionals, students and open source contributors to foster innovation.
Shift left
Terrascan by Tenable
With Terrascan, you can scan nearly all infrastructure as code (IaC) types for misconfigurations and compliance violations with more than 500 out-of-the-box policies. Terrascan leverages the Open Policy Agent (OPA) engine so you can easily create custom policies using the Rego query language. Integrate into your CI/CD, use locally or test code in your browser to see how effective preventive security can be. With 4,000 GitHub stars and 1.8 million downloads, Terrascan is one of the most beloved open source cloud security tools in the world.
This 45-second video shows how Terrascan reduces cloud exposures by scanning code that provisions cloud infrastructure.
Emulate adversaries
CNAPPgoat
CNAPPgoat is an open source project for safe testing of cloud security skills, processes and tools in an easy-to-deploy-and-destroy sandbox environment. This enables defenders to test detection and prevention mechanisms against vulnerabilities and misconfigurations, while providing offensive professionals practice environments. With a large and expanding library of scenarios, DevSecOps teams can validate defenses in customized environments and simulate unsecured and vulnerable assets.
Decode permissions
Access undenied AWS
Access Undenied on AWS is an open source command-line interface (CLI) tool that analyzes and gives context to AWS CloudTrail AccessDenied events. It works by scanning the environment to identify and explain event reasons and offers actionable least-privilege remediation suggestions. Give the tool a CloudTrail event with an “Access Denied” outcome, and it will tell you how to fix it within seconds.
Related products
Cloud Exposure (CNAPP)
Close cloud exposure with the actionable cloud security platform.
Related resources
See
Tenable
in action
See how Tenable can give your team the clarity to fix what matters, at the speed of AI.
- Tenable Cloud Security
Tenable One
Request a demo
The world’s leading AI-powered exposure management platform.
Thank You
Thank you for your interest in Tenable One.
A representative will be in touch soon.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success