socbox

Scan any public repo

Free. No login. Results in about three minutes.

12 scannersSAST + secrets + CVE + IaC~3 minutes
Allowed:github.comgitlab.comcodeberg.orggitea.com

Recent scans

6 of last 100 · refreshed just now

Threat intel · always live

Every scan enriches findings against the same intel feeds enterprise SOCs run. Updated continuously by socbox-intel-mirror.

  • 1,592
    CISA KEV
    hourly
  • 333,848
    FIRST EPSS
    daily
  • 668
    MITRE ATT&CK
    weekly
  • 969
    MITRE CWE
    monthly
  • 482
    CAPEC
    monthly
Team platformComing soon

The full security platform is on its way

The free scanner above is live today. Private-repository scanning, dashboards, and CI policy gates for teams are in active development.

  • Private-repo scanning

    Connect GitHub, GitLab, Gitea & Codeberg and scan private repositories on every push.

  • Dashboards & findings

    Triage, dedupe, and track findings across repos and images over time — not one-off reports.

  • Policy gates in CI

    Fail a build or block a deploy when a scan crosses your severity, license, or secrets policy.

  • Scheduled & continuous scans

    Re-scan on a cadence and on new CVE disclosures so regressions surface without a manual run.

  • SBOM & provenance

    Generate and store SBOMs, sign artifacts, and keep an auditable provenance trail per image.

  • SSO, roles & audit

    Team workspaces with SSO, role-based access, and audit-log streaming for compliance.

Want early access? Email hello@socbox.cloudNo account needed to use the public scanner — it stays free.