Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

https://github.com/Soluto/owasp-zap-glue-ci-images

Ready to use images of Zap and Glue, especially for CI integration.

ci docker-image owasp security-testing

Last synced: 05 Jul 2024

https://github.com/seungsoo-lee/DELTA

PROJECT DELTA: SDN SECURITY EVALUATION FRAMEWORK

pentesting sdn security-testing software-defined-networking

Last synced: 28 Jun 2024

https://github.com/aktsk/ipa-medit

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

applesilicon arsenal blackhat ios ios-security m1 mobile-app-security mobile-security-testing security-testing security-tools

Last synced: 26 Jun 2024

https://github.com/aktsk/apk-medit

memory search and patch tool on debuggable apk without root & ndk

android android-security arsenal blackhat mobile-app-security mobile-security-testing security-testing security-tools

Last synced: 26 Jun 2024

https://github.com/marcoagner/boast

The BOAST Outpost for AppSec Testing (v0.1.2)

appsec appsec-testing oast security security-testing security-tools

Last synced: 25 Jun 2024

https://github.com/Viralmaniar/Passhunt

Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.

cybersecurity default-credentials default-password password penetration-testing pentest-tool security security-testing

Last synced: 14 Jun 2024

https://github.com/jassics/security-study-plan

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...

api-security application-security appsec appsec-tutorials aws-security azure-security cybersecurity cybersecurity-education devsecops-university gcp-security infosec pentesting security-testing study-guide study-plan study-planner

Last synced: 07 Jun 2024

https://github.com/itboxltda/pentestlab

Script to manage and create local pentesting training virtual lab

cybersecurity cybersecurity-training-lab laboratory-automation owasp pentesting-resources security-testing

Last synced: 06 Jun 2024

https://github.com/opensec-cn/kunpeng

kunpeng是一个Golang编写的开源POC框架/库,以动态链接库的形式提供各种语言调用,通过此项目可快速开发漏洞检测类的系统。

poc-library proof-of-concept security-testing security-vulnerability

Last synced: 05 Jun 2024

https://github.com/0xisk/awesome-solidity-security

The purpose of this repo is to list all the related Research Papers focused on Smart-contracts security topics. As well as listing all the encountered smart-contracts defects with a summary description. 🛡️

awesome awesome-list ethereum-contract research-paper security security-testing security-topics security-vulnerability smart-contract-security smart-contracts smart-contracts-audit

Last synced: 22 May 2024

https://github.com/gdgd009xcd/automacrobuilder

A BurpSuite Add-on that allows testing of web application vulnerabilities by recording complex multi-step sequences. You can test applications that need to access pages in a specific order, such as shopping carts or registration of member information.

authentication burpsuite burpsuite-extender burpsuite-tools crawler extender extensions multi-step security security-testing security-tools vulnerability-scanners webcrawler websecurity

Last synced: 19 May 2024

https://github.com/openraven/magpie

A Cloud Security Posture Manager or CSPM with a focus on security analysis for the modern cloud stack and a focus on the emerging threat landscape such as cloud ransomware and supply chain attacks.

aws cloud cloudsecurity cspm gcp security security-audit security-scanner security-testing security-tools security-vulnerability

Last synced: 12 May 2024

https://github.com/gdgd009xcd/AutoMacroBuilderForZAP

A ZAPROXY Add-on that allows testing of web application vulnerabilities by recording complex multi-step sequences. You can test applications that need to access pages in a specific order, such as shopping carts or registration of member information.

activescan addon authentication csrf multistep multistep-form security security-testing security-tools vulnerability-scanners web-security webcrawler websecurity zap-extension zaproxy

Last synced: 12 May 2024

https://github.com/Contrast-Security-OSS/safelog4j

Safelog4j is an instrumentation-based security tool to help teams discover, verify, and solve log4shell vulnerabilities without scanning or upgrading

iast java log4j log4shell rasp security security-testing vulnerability vulnerability-scanner

Last synced: 12 May 2024

https://github.com/xen0l/dlint-check

Github Action to run dlint security linter on your Python code

flake8 github-actions linter python python3 security security-testing static-analysis

Last synced: 11 May 2024

https://github.com/sterrasec/dummy

Generator of static files for testing file upload. It can generate the png file of any number of bytes!

image-generation png-image-generate qa security-audit security-testing

Last synced: 02 May 2024

https://github.com/jay-johnson/owasp-jenkins

Want to test your applications using the latest OWASP security toolchains and the NIST National Vulnerability Database using Jenkins, Ansible and docker? :whale: :shield: :lock:

ansible c-sharp dependency-checker django docker jenkins national-vulnerability-database node nvd owasp python react ruby-on-rails security security-automation security-testing security-vulnerability tensorflow vue zap

Last synced: 20 Apr 2024

https://github.com/kpcyrd/boxxy-rs

Linkable sandbox explorer

regression-testing rust sandboxing security-testing

Last synced: 18 Apr 2024

https://github.com/akto-api-security/akto

Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure

api-discovery api-security api-security-testing api-testing authentication authorization devsecops devsecops-pipeline docker docker-compose hacktoberfest hacktoberfest2023 idor owasp-top-10 react security security-testing sensitive-data-exposure threat-detection

Last synced: 18 Apr 2024

https://github.com/CaringCaribou/caringcaribou

A friendly car security exploration tool for the CAN bus

can-bus ecu fuzzing python security-scanner security-testing xcp

Last synced: 17 Apr 2024

https://github.com/tprynn/web-methodology

Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki

application-security appsec documentation security security-testing web web-application web-application-security

Last synced: 12 Apr 2024

https://github.com/jjf012/gopoc

用cel-go重现了长亭xray的poc检测功能的轮子

poc proof-of-concept security-testing vulnerability-scanner

Last synced: 12 Apr 2024

https://github.com/B3nac/InjuredAndroid

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

android android-security android-studio apk bug-bounty ctf flutter flutter-security flutter-xss kotlin kotlin-android pentesting security-testing vulnerabilities webview

Last synced: 07 Apr 2024

https://github.com/iamprbkr/awesomebugbounty4noob

Awesome Resources for beginners on how to find websites/Domains/Targets for Bugbounty/Pentesting/Responsible Disclosure

bug-bounty bugbounty ethical-hacking pentesters security security-testing security-vulnerability

Last synced: 06 Apr 2024

https://github.com/bl4de/security-tools

My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.

bug-bounties bug-bounty bugbounty ctf ctf-tools hacking infosec itsecurity pentesting python scanner security-testing security-tools static-analysis webappsec

Last synced: 05 Apr 2024

https://github.com/wallarm/gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

api-security bugbounty graphql-security grpc-security owasp rest-security security security-testing security-tools waf web-application-firewall web-application-security

Last synced: 01 Apr 2024

https://github.com/falcosecurity/event-generator

Generate a variety of suspect actions that are detected by Falco rulesets

go kubernetes-auditing security security-testing syscall

Last synced: 22 Mar 2024

https://github.com/trailofbits/siderophile

Find the ideal fuzz targets in a Rust codebase

fuzzing program-analysis rust security-testing

Last synced: 16 Mar 2024