kubeek-sec
SECURITY // OPEN SOURCE // APPSEC · ASPM

KUBEEK//SEC

A community-minded collective making AppSec and ASPM easier for developers.

We integrate the best open-source security tools, make them all speak the same language, and give the result back to the people who build them. No commercial goal. No upsell. No open-core paywall.

// why we build

Application security is not short on tools.
It is short on coherence.

A serious look at a single codebase can touch a dozen scanners — SAST, SCA, secrets, IaC, license, malware, DAST, CI/CD — and every one has its own CLI, its own flags, its own output shape, its own idea of what "severity" means.

Stitching them together is a tax every team pays again from scratch, and it lands hardest on the developers who just want to ship safe code.

So our mission is deliberately unglamorous: take the best open-source security tools, make them easy to run, make them all speak the same language, and give the result back to the community.

AppSec — shift left

Find and fix issues in the code and its pipeline, as early and with as little friction as possible — where developers already work, not as a gate at the end.

ASPM — see the estate

Step back from a single repo to see security across a whole estate: what's exposed, where posture is improving or slipping, and what to fix first.

$ cat principles.txt
Standardize, don't reinvent. The detection engines are years of work by others — our job is to integrate and normalize them, not to reinvent them. We build for the love of the craft, and we give back.

// projects

[ 01 ] flagship Python

> deep-scan

A modular security-scanning monorepo. One engine, many front-ends — an MCP server for agents/IDEs, a CLI for local & CI, a REST API + web app, and a continuous-scanning fleet with an ASPM dashboard. 20+ scanners, one normalized finding model, four report formats (JSON · Markdown · HTML · SARIF).

github.com/kubeek-sec/deep-scan ↗
[ 02 ] Python · PHP

> canary

Canary endpoints — the only external addresses your code should contact during a security test. Non-malicious drop / exfiltration / info-collection paths that prove a hole exists before the fix, and is closed after. Hosted right here on kubeek.com.

github.com/kubeek-sec/canary ↗
[ 03 ] Python

> guinea-pig

A security-scanner test bed. Intentionally-vulnerable fixtures, one CWE per directory, each paired with its remediation — plus DAST, LLM and CI/CD fixtures and centralized ground truth for benchmarking scanner recall and precision.

github.com/kubeek-sec/guinea-pig ↗
[ 04 ] Jupyter

> patchnoisseur

cve-diff — builds a Parquet dataset that links every NVD CVE to its fixing-commit diff, its description and its CWEs. Auto-healing, parallel fetchers pulling patches from GitHub, GitLab, Gitee and cgit. The data behind smarter patch analysis.

github.com/kubeek-sec/patchnoisseur ↗
[ 05 ] HTML · Python

> pci

Packet Communication Investigator. Collect network traffic into a graph database and explore machine-to-network interactions on a graph — enriched with reverse DNS, country and ASN. PCAP, live and ring-buffer capture. For educational use.

github.com/kubeek-sec/pci ↗

// live on this host

Canary endpoints — running on kubeek.com

This domain hosts the canary endpoints. They are not malicious — they only let a security test prove a drop / exfiltration / info-collection path exists before a fix, and is closed after.

[email protected] — endpoints
GET · POST /info/ Method / reachability echo — a simple outbound-HTTP beacon.
GET /monip/ Origin IP as seen across X-Forwarded-For, CF-Connecting-IP, REMOTE_ADDR.
GET /run/download.php?file=run.sh Drop via PHP by name — run.sh · run.ps1 · run.txt.
GET /run/run.sh Direct download of the inert staging script.

Note: the served scripts are inert (echo "It runs!"). The site is fronted by Cloudflare, which rejects requests with no User-Agent (403) — always send one.

// get involved

Built for the love of the craft.

Everything is open source. Star it, fork it, file an issue, or just read the code. Security should be a little less painful — for everyone.