Open Source Security Tools

Building tools that solve real security engineering problems. Practical automation for CloudTrail analysis, compliance workflows, and dependency management.

TrailTool

CloudTrail for AI agents

Pre-aggregates CloudTrail events into entities (People, Sessions, Roles, Services, Resources) for fast AI-driven security analysis. Answers questions like "What did Alex do yesterday?" without overwhelming AI agents with thousands of raw events.

Status: Early access at trailtool.io

Read the launch post →

GraphGRC

SOC 2 compliance in GitHub

Pre-written SOC 2 controls, policies, processes, and standards in Markdown with semantic linking. Fork the repo, customize for your company, generate a compliance site with GitHub Actions. Your compliance documentation in version control, not a proprietary SaaS platform.

Status: Available at engseclabs.com/graphgrc/docs

View on GitHub | Read the launch post →

Dependabot Wolf

Fix security alerts that don't open PRs

GitHub Action that monitors Dependabot security alerts and automatically creates issues with Copilot assignments when Dependabot can't open a pull request. Handles dependency conflicts and complex update scenarios automatically.

Status: Available at github.com/engseclabs/dependabot-wolf

Read more →

Get in Touch

Whether you're looking for help with a specific security challenge or want to discuss building out your security program, we'd like to hear from you. Reach out at:

Or use this form to tell us about what you're working on: