An open API service indexing awesome lists of open source software.

venom

👽 The collection of awesome software, tools, libraries, documents, books, resources and cool stuff about information security, penetration testing and offensive cybersecurity.
https://github.com/kraloveckey/venom

Last synced: 18 days ago
JSON representation

  • Analysis Tools

    • `peepdf` - Python tool to explore PDF files in order to find out if the file can be harmful or not.
    • `Veles` - Binary data visualization and analysis tool.
    • `CyberChef` - The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis.
    • `DocBleach` - An open-source Content Disarm & Reconstruct software sanitizing Office, PDF and RTF Documents.
    • `ExifTool` - Platform-independent Perl library plus a command-line application for reading, writing and editing meta information in a wide variety of files.
    • `pompelmi` - source route-level upload security for Node.js teams that need to inspect untrusted files before disk, object storage, previews, or downstream parsers. can files before storage to detect malware, MIME spoofing, and risky archives.
  • Anonymity / Tor Tools

    • `Metadata Anonymization Toolkit (MAT)` - Metadata removal tool, supporting a wide range of commonly used file formats, written in Python3.
    • `OnionScan` - Tool for investigating the Dark Web by finding operational security issues introduced by Tor hidden service operators.
    • `Tor` - Free software and onion routed overlay network that helps you defend against traffic analysis.
    • `dos-over-tor` - Proof of concept denial of service over Tor stress test tool.
    • `kalitorify` - Transparent proxy through Tor for Kali Linux OS.
    • `Nipe` - Script to redirect all traffic from the machine to the Tor network.
    • `What Every Browser Knows About You` - Comprehensive detection page to test your own Web browser's configuration for privacy and identity leaks.
    • `I2P` - The Invisible Internet Project.
    • `Tails` - Live operating system aiming to preserve your privacy and anonymity.
  • Anti-virus Evasion Tools

    • `Shellter` - Dynamic shellcode injection tool, and the first truly dynamic PE infector ever created.
    • `UniByAv` - Simple obfuscator that takes raw shellcode and generates Anti-Virus friendly executables by using a brute-forcable, 32-bit XOR key.
    • `Veil` - Generate metasploit payloads that bypass common anti-virus solutions.
    • `AntiVirus Evasion Tool (AVET)` - Post-process exploits containing executable files targeted for Windows machines to avoid being recognized by antivirus software.
    • `CarbonCopy` - Tool that creates a spoofed certificate of any online website and signs an Executable for AV evasion.
    • `peCloakCapstone` - Multi-platform fork of the `peCloak.py` automated malware antivirus evasion tool.
    • `Shellter` - Dynamic shellcode injection tool, and the first truly dynamic PE infector ever created.
  • Cloud Platform Attack Tools

    • `HackingThe.cloud`
    • `Cloud Container Attack Tool (CCAT)` - Tool for testing security of container environments.
    • `CloudHunter` - Looks for AWS, Azure and Google cloud storage buckets and lists permissions for vulnerable buckets.
    • `cloudsploit` - source project designed to allow detection of security risks in cloud infrastructure accounts, including: Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI), and GitHub. These scripts are designed to return a series of potential misconfigurations and security risks.
    • `GCPBucketBrute` - Script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.
  • Collaboration Tools

    • `Lair` - Reactive attack collaboration framework and web application built with meteor.
    • `Reconmap` - Open-source collaboration platform for InfoSec professionals that streamlines the pentest process.
    • `cset` - by-step process to collect facility-specific information addressing topics such as hardware, software, administrative policies, and user obligations. It then compares that information to relevant security standards and regulations, assesses overall compliance, and provides appropriate recommendations for improving cybersecurity posture. The tool pulls its recommendations from a collection of the best available cybersecurity standards, guidelines, and practices. Where appropriate, recommendations are linked to a set of actions that can be applied to enhance cybersecurity controls.
    • `Pentest Collaboration Framework (PCF)` - Open source, cross-platform, and portable toolkit for automating routine pentest processes with a team.
    • `RedELK` - Track and alarm about Blue Team activities while providing better usability in long term offensive operations.
    • `sysreptor`
  • CTF Tools / Resources / Courses

    • `Awesome CTF` - A curated list of CTF frameworks, libraries, resources and software.
    • `Hack The Box` - An online cybersecurity training platform allowing IT professionals to advance their ethical hacking skills and be part of a worldwide community.
    • `Offensive Security Training` - Training from BackTrack/Kali developers.
    • `OverTheWire War Games` - The wargames offered by the OverTheWire community can help you to learn and practice security concepts in the form of fun-filled games.
    • `Roppers Academy Training` - Free courses on computing and security fundamentals designed to train a beginner to crush their first CTF.
    • `TryHackMe` - Online platform for learning cyber security, using hands-on exercises and labs.
    • `Awesome Cyber Skills` - A curated list of hacking environments where you can train your cyber skills legally and safely.
    • `CTF Field Guide` - Everything you need to win your next CTF competition.
    • `leaked-system-prompts`
    • `PayloadsAllTheThings` - A list of useful payloads and bypass for Web Application Security and Pentest/CTF
    • `RsaCtfTool` - Decrypt data enciphered using weak RSA keys, and recover private keys from public keys using a variety of automated attacks.
    • `shellpop` - Easily generate sophisticated reverse or bind shell commands to help you save time during penetration tests.
    • `Ciphey` - Automated decryption tool using artificial intelligence and natural language processing.
    • `SANS Security Training` - Computer Security Training & Certification.
    • `Arizona Cyber Warfare Range` - 24x7 live fire exercises for beginners through real world operations; capability for upward progression into the real world of cyber warfare.
    • `Open Security Training` - Training material for computer security classes.
  • Databases

    • `PGTune` - Tuning PostgreSQL config by your hardware.
  • Datastores

    • `databunker` - Databunker is an address book on steroids for storing personal data. GDPR and encryption are out of the box.
    • `nextcloud` - A safe home for all your data.
    • `passbolt` - The password manager your team was waiting for. Free, open source, extensible, based on OpenPGP.
    • `acra` - Database security suite: proxy for data protection with transparent "on the fly" data encryption, data masking and tokenization, SQL firewall (SQL injections prevention), intrusion detection system.
    • `aws-vault` - Store AWS credentials in the OSX Keychain or an encrypted file
    • `blackbox` - Safely store secrets in a VCS repo using GPG
    • `chamber` - Store secrets using AWS KMS and SSM Parameter Store
    • `confidant` - Stores secrets in AWS DynamoDB, encrypted at rest and integrates with IAM
    • `credstash` - Store secrets using AWS KMS and DynamoDB
    • `dotgpg` - A tool for backing up and versioning your production secrets or shared passwords securely and easily.
    • `LunaSec` - Database for PII with automatic encryption/tokenization, sandboxed components for handling data, and centralized authorization controls.
    • `passpie` - Multiplatform command-line password manager
    • `pwndrop` - Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.
    • `redoctober` - Server for two-man rule style file encryption and decryption.
    • `Sops` - An editor of encrypted files that supports YAML, JSON and BINARY formats and encrypts with AWS KMS and PGP.
    • `Vault` - An encrypted datastore secure enough to hold environment and application secrets.
    • `Yopass` - Secure sharing of secrets, passwords and files.
    • `aliasvault` - first password manager with built-in email aliasing. Fully encrypted and self-hostable.
    • `TeamPass` - Premise.
  • Emails

  • Endpoint

    • Anti-Virus / Anti-Malware

      • `Awesome Malware Analysis` - A curated list of awesome malware analysis tools and resources.
      • `ClamAv` - ClamAV® is an open-source antivirus engine for detecting trojans, viruses, malware & other malicious threats.
      • `Linux Malware Detect` - A malware scanner for Linux designed around the threats faced in shared hosted environments.
      • `Fastfinder` - Fast customisable cross-platform suspicious file finder. Supports md5/sha1/sha256 hashs, litteral/wildcard strings, regular expressions and YARA rules. Can easily be packed to be deployed on any windows / linux host.
      • `gocheck` - A golang implementation of Matterpreter's [`DefenderCheck`](https://github.com/matterpreter/DefenderCheck) that aims to aid red teams in their malware development capabilities by identifying the exact bytes in their malware that are flagged by security solutions.
      • `LOKI` - Simple Indicators of Compromise and Incident Response Scanner.
      • `rkhunter` - A Rootkit Hunter for Linux.
    • Authentication

      • `FreeOTP` - A two-factor authentication application for systems utilizing one-time password protocols. Tokens can be added easily by scanning a QR code.
      • `google-authenticator` - The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms, as well as a pluggable authentication module (PAM). One-time passcodes are generated using open standards developed by the Initiative for Open Authentication (OATH) (which is unrelated to OAuth). These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (TOTP) algorithm specified in RFC 6238. [Tutorials: How to set up two-factor authentication for SSH login on Linux](http://xmodulo.com/two-factor-authentication-ssh-login-linux.html)
      • `Stegcloak` - Securely assign Digital Authenticity to any written text
    • Configuration Management

      • `Fleet device management` - Fleet is the lightweight, programmable telemetry platform for servers and workstations. Get comprehensive, customizable data from all your devices and operating systems.
      • `GLPi` - Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.
    • Forensics

      • `mig` - MIG is a platform to perform investigative surgery on remote endpoints. It enables investigators to obtain information from large numbers of systems in parallel, thus accelerating investigation of incidents and day-to-day operations security.
      • `Awesome Forensics` - Free (mostly open source) forensic analysis tools and resources.
      • `grr` - GRR Rapid Response is an incident response framework focused on remote live forensics.
      • `ir-rescue` - *ir-rescue* is a Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.
      • `Logdissect` - CLI utility and Python API for analyzing log files and other data.
      • `Maigret` - Maigret collect a dossier on a person by username only, checking for accounts on a huge number of sites and gathering all the available information from web pages.
      • `Meerkat` - PowerShell-based Windows artifact collection for threat hunting and incident response.
      • `Rekall` - The Rekall Framework is a completely open collection of tools, implemented in Python under the Apache and GNU General Public License, for the extraction and analysis of digital artifacts computer systems.
      • `Volatility` - Python based memory extraction and analysis framework.
      • `url-sandbox` - Scalable URL Sandbox for analyzing URLs and Domains from phishing attacks.
      • `LiME` - Linux Memory Extractor
    • Mobile / Android / iOS

      • `android-security-awesome` - A collection of android security related resources. A lot of work is happening in academia and industry on tools to perform dynamic analysis, static analysis and reverse engineering of android apps.
      • `dotPeek` - Free-of-charge standalone tool based on ReSharper's bundled decompiler.
      • `Themis` - High-level multi-platform cryptographic framework for protecting sensitive data: secure messaging with forward secrecy and secure data storage (AES256GCM), suits for building end-to-end encrypted applications.
      • `Android Exploits` - Guide on Android Exploitation and Hacks.
      • `AMExtractor` - AMExtractor can dump out the physical content of your Android device even without kernel source code.
      • `Android Storage Extractor` - A tool to extract local data storage of an Android application in one click.
      • `Apktool` - A tool for reverse engineering Android apk files.
      • `enjarify` - A tool for translating Dalvik bytecode to equivalent Java bytecode.
      • `frida` - Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.
      • `hardened_malloc` - Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.
      • `jadx` - Command line and GUI tools for produce Java source code from Android Dex and Apk files.
      • `OSX Security Awesome` - A collection of OSX and iOS security resources
      • `OWASP Mobile Security Testing Guide` - A comprehensive manual for mobile app security testing and reverse engineering.
      • `symbiote` - Your target's phone's front and back cameras can be accessed by sending a link.
      • `Quark-Engine` - An Obfuscation-Neglect Android Malware Scoring System.
      • `reFlutter` - Flutter Reverse Engineering Framework.
      • `SecMobi Wiki` - A collection of mobile security resources which including articles, blogs, books, groups, projects, tools and conferences. *
      • `UDcide` - Android Malware Behavior Editor.
      • `Mobile Security Wiki` - A collection of mobile security resources.
  • Exfiltration Tools

    • Forensics

      • `Iodine` - Tunnel IPv4 data through a DNS server; useful for exfiltration from networks where Internet access is firewalled, but DNS queries are allowed.
      • `DET` - Proof of concept to perform data exfiltration using either single or multiple channel(s) at the same time.
      • `dnscat2` - Tool designed to create an encrypted command and control channel over the DNS protocol, which is an effective tunnel out of almost every network.
      • `pwnat` - Punches holes in firewalls and NATs.
      • `QueenSono` - Client/Server Binaries for data exfiltration with ICMP. Useful in a network where ICMP protocol is less monitored than others (which is a common case).
      • `TrevorC2` - Client/server tool for masking command and control and data exfiltration through a normally browsable website, not typical HTTP POST requests.
      • `tgcd` - Simple Unix network utility to extend the accessibility of TCP/IP based network services beyond firewalls.
  • Exploit Development Tools

    • Forensics

      • `Magic Unicorn` - Shellcode generator for numerous attack vectors, including Microsoft Office macros, PowerShell, HTML applications (HTA), or `certutil` (using fake certificates).
      • `peda` - Python Exploit Development Assistance for GDB.
      • `Pwntools` - Rapid exploit development framework built for use in CTFs.
      • `VcenterKit` - Vcenter Comprehensive Penetration and Exploitation Toolkit.
      • `Wordpress Exploit Framework` - Ruby framework for developing and using modules which aid in the penetration testing of WordPress powered websites and systems.
  • Hash Cracking Tools

    • Forensics

      • `CeWL` - Generates custom wordlists by spidering a target's website and collecting unique words.
      • `crackstation` - Password Hash Cracker.
      • `Rar Crack` - RAR bruteforce cracker.
      • `BruteForce Wallet` - Find the password of an encrypted wallet file (i.e. `wallet.dat`).
      • `duplicut` - Quickly remove duplicates, without changing the order, and without getting OOM on huge wordlists.
      • `GoCrack` - Management Web frontend for distributed password cracking sessions using hashcat (or other supported tools) written in Go.
      • `hate_crack` - Tool for automating cracking methodologies through Hashcat.
      • `JWT Cracker` - Simple HS256 JSON Web Token (JWT) token brute force cracker.
      • `pydictor` - A powerful and useful hacker dictionary builder for a brute-force attack.
      • `John the Ripper` - Fast password cracker.
  • Hex Editors

    • Forensics

      • `Hexinator` - World's finest (proprietary, commercial) Hex Editor.
      • `wxHexEditor` - Free GUI hex editor for GNU/Linux, macOS, and Windows.
      • `Bless` - High quality, full featured, cross-platform graphical hex editor written in Gtk#.
      • `hexedit` - Simple, fast, console-based hex editor.
      • `Frhed` - Binary file editor for Windows.
  • Intentionally Vulnerable Systems

  • Multi-paradigm Frameworks

    • Forensics

      • `Armitage` - Java-based GUI front-end for the Metasploit Framework.
      • `Metasploit` - Software for offensive security teams to help verify vulnerabilities and manage security assessments.
      • `AutoSploit` - Automated mass exploiter, which collects target by employing the Shodan API and programmatically chooses Metasploit exploit modules based on the Shodan query.
      • `Decker` - Penetration testing orchestration and automation framework, which allows writing declarative, reusable configurations capable of ingesting variables and using outputs of tools it has run as inputs to others.
      • `Faraday` - Multiuser integrated pentesting environment for red teams performing cooperative penetration tests, security audits, and risk assessments.
      • `Metasploit Framework` - A tool for developing and executing exploit code against a remote target machine. Other important sub-projects include the Opcode Database, shellcode archive and related research.
      • `Pupy` - Cross-platform (Windows, Linux, macOS, Android) remote administration and post-exploitation tool.
  • Network

    • Anti-Spam

      • `Spam Scanner` - Anti-Spam Scanning Service and Anti-Spam API.
      • `SpamAssassin` - A powerful and popular email spam filter employing a variety of detection technique.
      • `rspamd` - Fast, free and open-source spam filtering system.
    • DDoS Tools

      • `Anevicon` - Powerful UDP-based load generator, written in Rust.
      • `HOIC` - Updated version of Low Orbit Ion Cannon, has 'boosters' to get around common counter measures.
      • `T50` - Faster network stress tool.
      • `DDoS-Ripper` - Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic.
      • `Ddosify` - Effortless Kubernetes Monitoring and Performance Testing. Available on CLI, Self-Hosted, and Cloud.
      • `Finshir` - A coroutines-driven Low & Slow traffic generator, written in Rust.
      • `Impulse` - Modern Denial-of-service ToolKit.
      • `Low Orbit Ion Canon (LOIC)` - Open source network stress tool written for Windows.
      • `Memcrashed` - DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API.
      • `SlowLoris` - DoS tool that uses low bandwidth on the attacking side.
      • `UFONet` - Abuses OSI layer 7 HTTP to create/manage 'zombies' and to conduct different attacks using; `GET`/`POST`, multithreading, proxies, origin spoofing methods, cache evasion techniques, etc.
    • Firewall

      • `fwknop` - Protects ports via Single Packet Authorization in your firewall.
      • `ipset` - Framework inside the Linux kernel, which can be administered by the ipset utility. Depending on the type, an IP set may store IP addresses, networks, (TCP/UDP) port numbers, MAC addresses, interface names or combinations of them in a way, which ensures lightning speed when matching an entry against a set.
      • `OPNsense` - is an open source, easy-to-use and easy-to-build FreeBSD based firewall and routing platform. OPNsense includes most of the features available in expensive commercial firewalls, and more in many cases. It brings the rich feature set of commercial offerings with the benefits of open and verifiable sources.
      • `pfSense` - Firewall and Router FreeBSD distribution.
      • `blocklist-ipsets` - ipsets dynamically updated with firehol's update-ipsets.sh script.
    • Forensics

      • `dsniff` - Collection of tools for network auditing and pentesting.
      • `Intercepter-NG` - Multifunctional network toolkit.
      • `Ncrack` - High-speed network authentication cracking tool built to help companies secure their networks by proactively testing all their hosts and networking devices for poor passwords.
      • `Praeda` - Automated multi-function printer data harvester for gathering usable data during security assessments.
      • `network-segmentation-cheat-sheet` - This project was created to publish the best practices for segmentation of the corporate network of any company. In general, the schemes in this project are suitable for any company.
      • `CrackMapExec` - Swiss army knife for pentesting networks.
      • `dnstwist` - Domain name permutation engine for detecting typo squatting, phishing and corporate espionage.
      • `IKEForce` - Command line IPSEC VPN brute forcing tool for Linux that allows group name/ID enumeration and XAUTH brute forcing capabilities.
      • `Intercepter-NG` - Multifunctional network toolkit.
      • `Legion` - Graphical semi-automated discovery and reconnaissance framework based on Python 3 and forked from SPARTA.
      • `NetExec` - Network service exploitation tool that helps automate assessing the security of large networks.
      • `Network-Tools.com` - Website offering an interface to numerous basic network utilities like `ping`, `traceroute`, `whois`, and more.
      • `pivotsuite` - Portable, platform independent and powerful network pivoting toolkit.
      • `Praeda` - Automated multi-function printer data harvester for gathering usable data during security assessments.
      • `Printer Exploitation Toolkit (PRET)` - Tool for printer security testing capable of IP and USB connectivity, fuzzing, and exploitation of PostScript, PJL, and PCL printer language features.
      • `routersploit` - Open source exploitation framework similar to Metasploit but dedicated to embedded devices.
      • `rshijack` - TCP connection hijacker, Rust rewrite of `shijack`.
      • `SigPloit` - Signaling security testing framework dedicated to telecom security for researching vulnerabilites in the signaling protocols used in mobile (cellular phone) operators.
      • `THC Hydra` - Online password cracking tool with built-in support for many network protocols, including HTTP, SMB, FTP, telnet, ICQ, MySQL, LDAP, IMAP, VNC, and more.
      • `Tsunami` - General purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
      • `Zarp` - Network attack tool centered around the exploitation of local networks.
    • Honey Pot / Honey Net

      • `awesome-honeypots` - The canonical awesome honeypot list.
      • `Conpot` - ICS/SCADA Honeypot. Conpot is a low interactive server side Industrial Control Systems honeypot designed to be easy to deploy, modify and extend. By providing a range of common industrial control protocols we created the basics to build your own system, capable to emulate complex infrastructures to convince an adversary that he just found a huge industrial complex. To improve the deceptive capabilities, we also provided the possibility to server a custom human machine interface to increase the honeypots attack surface. The response times of the services can be artificially delayed to mimic the behaviour of a system under constant load. Because we are providing complete stacks of the protocols, Conpot can be accessed with productive HMI's or extended with real hardware. Conpot is developed under the umbrella of the Honeynet Project and on the shoulders of a couple of very big giants.
      • `Amun` - Amun Python-based low-interaction Honeypot.
      • `Conpot` - ICS/SCADA Honeypot. Conpot is a low interactive server side Industrial Control Systems honeypot designed to be easy to deploy, modify and extend. By providing a range of common industrial control protocols we created the basics to build your own system, capable to emulate complex infrastructures to convince an adversary that he just found a huge industrial complex. To improve the deceptive capabilities, we also provided the possibility to server a custom human machine interface to increase the honeypots attack surface. The response times of the services can be artificially delayed to mimic the behaviour of a system under constant load. Because we are providing complete stacks of the protocols, Conpot can be accessed with productive HMI's or extended with real hardware. Conpot is developed under the umbrella of the Honeynet Project and on the shoulders of a couple of very big giants.
      • `Cuckoo Sandbox` - Cuckoo Sandbox is an Open Source software for automating analysis of suspicious files. To do so it makes use of custom components that monitor the behavior of the malicious processes while running in an isolated environment.
      • `Glastopf` - Glastopf is a Honeypot which emulates thousands of vulnerabilities to gather data from attacks targeting web applications. The principle behind it is very simple: Reply the correct response to the attacker exploiting the web application.
      • `HoneyPy` - HoneyPy is a low to medium interaction honeypot. It is intended to be easy to: deploy, extend functionality with plugins, and apply custom configurations.