$ defensive.works

Security tooling
for practitioners

Automation, detection engineering, and open source security tools. Built from real production experience across 300+ AWS accounts.

scanner operational
docs live
platform in development
Tool
GHA Scanner

GitHub Actions security scanner. 25 checks across 8 categories. Scan any public repo, get a detailed report with remediation steps. No sign-up required.

live supply chain injection permissions secrets
Documentation
Docs

Security automation playbooks, AWS detection engineering, incident response tooling. Written from production, not theory.

aws detection cloudtrail iam
Source
Open Source

Everything is open source. The scanner engine, the checks, the docs. Fork it, extend it, use it.

github python cdk
What's next

Defensive Works is becoming a platform. Interactive labs, guided detection engineering, hands-on cloud security training. A place to learn by building, not by watching.