## Open-Source Projects

#### Prisma® Cloud by Palo Alto Networks is committed to open source and the community behind our open-source tools and the tools we support.

- [Visit our GitHub page](https://github.com/PaloAltoNetworks)

**prisma**  
Committed to Open Source

## We're dedicated to simplifying and securing your cloud-native applications, and open source is part of this mission. Our cutting-edge, open-source tools are designed to champion cloud-native best practices with a focus on enhancing security.

[Visit our GitHub page](https://github.com/bridgecrewio)

## PRISMA CLOUD OPEN SOURCE

## Key open-source contributions

### Checkov

### Extensible policy as code
Checkov is a command-line interface (CLI) that scans infrastructure as code (IaC) for misconfigurations and exposed secrets. Coverage includes Terraform®, Terraform plan, CloudFormation, Kubernetes®, Dockerfile, serverless and ARM templates and more.

- Integrate as a guardrail for CI/CD pipelines.
- Include graph-based analysis for context-aware policies.
- Add custom policies in Python or YAML.

[Learn more](https://github.com/bridgecrewio/checkov)

### Yor

### Automated tag-and-trace
Yor tags IaC templates with attribution and ownership details, unique IDs that get carried across to cloud resources, improving root cause analysis, operational efficiency and financial attribution.

- Automate tagging as a pre-commit hook or in a CI/CD pipeline.
- Include tracing details to decrease mean time to resolution (MTTR).
- Add custom tags for your own attribute needs.

[Learn more](https://github.com/bridgecrewio/yor)

### CI/CD Goat

### Deliberately vulnerable CI/CD environment. Hack CI/CD pipelines, capture the flags.
The CI/CD Goat project offers a practical, engaging way to learn CI/CD security with 11 hands-on challenges in a real CI/CD environment. Participants can deepen their expertise across various security risks through scenarios that progressively increase in difficulty.

- Tackle 11 targeted challenges in an authentic CI/CD setting.
- Learn to mitigate the OWASP Top 10 CI/CD Security Risks through interactive, scenario-based exercises.
- Enjoy a unique learning experience with each challenge themed after a character from “Alice in Wonderland.”

[Learn more](https://github.com/cider-security-research/cicd-goat)

### AirIAM

### Least privilege AWS® IAM using Terraform
AirIAM scans AWS IAM for activity and generates a Terraform template with least-privilege access.

- Reduce the attack surface by identifying unused users, roles and permissions.
- Generate usage-based policies for least-privileged access.
- Create Terraform code for IAM policies for version control and collaboration.

[Learn more](https://github.com/bridgecrewio/airiam)

## Additional Open-Source Projects

### TerraGoat
Vulnerable-by-design Terraform files for training and learning.
[Learn more](https://github.com/bridgecrewio/terragoat)

### WireLurkerDetector
Script for detecting the WireLurker malware family.
[Learn more](https://github.com/PaloAltoNetworks/WireLurkerDetector)

### RBAC-Police
Evaluate the RBAC permissions of Kubernetes identities through policies written in Rego.
[Learn more](https://github.com/PaloAltoNetworks/rbac-police)

### IronSkillet
IronSkillet is a set of day-one configuration templates for PAN-OS® to enable alignment with security best practices.
[Learn more](https://github.com/PaloAltoNetworks/iron-skillet)

### CFNGoat
Vulnerable-by-design CloudFormation files for training and learning.
[Learn more](https://github.com/bridgecrewio/cfngoat)

### Prisma Cloud CSPM Terraform provider
Terraform provider to provision and manage Prisma Cloud CSPM.
[Learn more](https://registry.terraform.io/providers/PaloAltoNetworks/prismacloud/latest)

### Prisma Enhanced Remediation
Create custom autoremediation solutions using serverless functions in the cloud.
[Learn more](https://github.com/PaloAltoNetworks/Prisma-Enhanced-Remediation)

### CDKGoat
Vulnerable-by-design AWS CDK files for training and learning.
[Learn more](https://github.com/bridgecrewio/cdkgoat)

### Prisma Cloud Compute Terraform provider
Terraform provider to manage Compute configurations and rulesets.
[Learn more](https://registry.terraform.io/providers/PaloAltoNetworks/prismacloudcompute/latest)

### Prisma Cloud Compute Operator
Kubernetes and OpenShift operator to deploy and manage Compute consoles and Defenders.
[Learn more](https://operatorhub.io/operator/pcc-operator)

### Prisma Cloud Compute GitHub Action
Scan container images using GitHub Actions.
[Learn more](https://github.com/marketplace/actions/prisma-cloud-scan)

### Prisma Cloud Compute GitLab integration
Example code for scanning container images from GitLab.
[Learn more](https://github.com/twistlock/sample-code/tree/master/CI/GitLab)

### Prisma Cloud Compute Codefresh Integration
Run a container image scan from your Codefresh pipelines.
[Learn more](https://github.com/twistlock/sample-code/tree/master/CI/Codefresh)

### Prisma Cloud Compute Travis CI integration
Example code for scanning container images from Travis CI.
[Learn more](https://github.com/twistlock/sample-code/tree/master/CI/Travis_CI)

### Cloud Offensive Breach and Risk Assessment (COBRA)
Simulate attacks across multi-cloud environments to provide a thorough assessment of security controls.
[Learn more](https://github.com/PaloAltoNetworks/cobra-tool)
