Skip to main content

Open source

The parts we think everyone should have.

Some of what we build is infrastructure rather than product — the models, parsers and primitives a defender needs before any of this is possible. Those we release.

Repositories

Supply chain defense

Tools that inspect what your build actually pulls in, written in response to attacks we had to answer for ourselves.

Vulnerability intelligence

Prioritization and detection research — the same reachability thinking that drives how our products rank findings.

Research and training

Deliberately breakable targets and practical utilities we use to teach, test detections, and validate tooling.

Why we release it

Defenders shouldn’t have to rebuild the same primitives.

Threat models, attack-path representations and cloud resource parsers are shared infrastructure. Keeping them proprietary slows everyone down, including us — and code that is read by strangers gets better.

Contributing

Every project is developed in the open on GitHub. Issues and pull requests go to the repository they concern.

Security policy

Report a vulnerability in any repository to security@rapticore.com. We acknowledge within one business day and follow coordinated disclosure.

Licensing

The license each repository carries is shown beside its name above. MIT and Apache-2.0 both permit commercial use.

Read the code. Then see the platform.