GHAYMAH CLI V2

DevSecOps Security & Compliance Command Center

Enterprise Security Assessment & Build Verification

Continuous DevSecOps Telemetry & Threat Posture

A consolidated audit ecosystem uniting binary reverse engineering, pre-deploy Docker security scanning, cloud S3 object storage validation, and web infrastructure hardening for the Ghaymah Cloud Platform and Ghaymah CLI V2.

ELF: gy-linux-amd64 TLS: TLS 1.3 Enforced S3 Ingress: Port 9000 Isolated Docker Scanner: Active (Blocks .env)
Evaluations
78
Across 12 categories
Critical
6
Immediate P0 Fixes
High
14
Priority 1 Action
Medium
20
Hardening & WAF
Passed Controls
36
Verified Defenses
Health Score
65.6%
Baseline Posture

Vulnerability Severities

Distribution of evaluated issues across risk tiers

78 Total
Critical (6)
High (14)
Medium (20)
Pass/Low (38)

Issues Across Architecture Domains

Evaluations across Docker, Networking, CI/CD, Storage, and AppSec

12 Domains
Highest density in Input Validation (8), Sensitive Files (8), and Networking (9). 100% Non-Destructive

Cross-Referenced Navigation Matrix

Direct links to authoritative audit artifacts, testing playbooks, and raw spreadsheets

Click any card to view detailed markdown reports

Consolidated Audit Findings Matrix

Extracted from Audit_Matrix.csv — Filterable by Severity, Domain Category, or Status

Finding ID Category CWE / MITRE Ref Severity Status Affected Component Detail Report
Showing 78 of 78 findings Fast Client-Side Instant Filtering

Interactive DevSecOps Glossary & Threat Legend

Hover or click on any term to understand security classifications and industry benchmarks

Standardized Lexicon
CWE (Common Weakness Enumeration)

A community-developed taxonomy of software and hardware weakness types (e.g. CWE-312: Cleartext Storage, CWE-20: Improper Input Validation).

MITRE ATT&CK (Adversary Tactics & Techniques)

A globally accessible knowledge base of adversary tactics and techniques based on real-world observations (e.g. T1557: Adversary-in-the-Middle).

Shift-Left Security (DevSecOps Integration)

Moving security testing, linting, and vulnerability scanning earlier in the software development lifecycle (in pre-commit or CLI pre-deploy).

SAST vs DAST (Static vs Dynamic Testing)

SAST: Analyzes source code without executing it (white-box). DAST: Tests running web applications externally without source access (black-box).

CVSS v3.1 (Common Vulnerability Scoring)

Open framework for communicating the characteristics and severity of software vulnerabilities on a scale from 0.0 to 10.0.

WORM / Immutability (Write Once, Read Many)

Storage technology ensuring audit logs or backup snapshots cannot be altered, overwritten, or deleted during their retention lifecycle.