An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with security-testing

A curated list of projects in awesome lists tagged with security-testing .

https://github.com/jassics/security-study-plan

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...

api-security application-security appsec appsec-tutorials aws-security azure-security cybersecurity cybersecurity-education devsecops-university gcp-security infosec pentesting security-testing study-guide study-plan study-planner

Last synced: 27 Jul 2025

https://github.com/opensec-cn/kunpeng

kunpeng是一个Golang编写的开源POC框架/库,以动态链接库的形式提供各种语言调用,通过此项目可快速开发漏洞检测类的系统。

poc-library proof-of-concept security-testing security-vulnerability

Last synced: 15 May 2025

https://github.com/wallarm/gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

api-security bugbounty graphql-security grpc-security owasp rest-security security security-testing security-tools waf web-application-firewall web-application-security

Last synced: 14 May 2025

https://github.com/Viralmaniar/Passhunt

Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.

cybersecurity default-credentials default-password password penetration-testing pentest-tool security security-testing

Last synced: 19 Jul 2025

https://github.com/viralmaniar/passhunt

Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.

cybersecurity default-credentials default-password password penetration-testing pentest-tool security security-testing

Last synced: 12 Apr 2025

https://github.com/akto-api-security/akto

Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure

api-discovery api-security api-security-testing api-testing authentication authorization devsecops devsecops-pipeline hacktoberfest hacktoberfest2023 idor owasp-top-10 security security-testing sensitive-data-exposure threat-detection

Last synced: 24 Dec 2025

https://github.com/bl4de/security-tools

My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.

bug-bounties bug-bounty bugbounty ctf ctf-tools hacking infosec itsecurity pentesting python scanner security-testing security-tools static-analysis webappsec

Last synced: 02 Apr 2025

https://github.com/caringcaribou/caringcaribou

A friendly car security exploration tool for the CAN bus

can-bus ecu fuzzing python security-scanner security-testing xcp

Last synced: 02 Apr 2025

https://github.com/CaringCaribou/caringcaribou

A friendly car security exploration tool for the CAN bus

can-bus ecu fuzzing python security-scanner security-testing xcp

Last synced: 08 May 2025

https://github.com/B3nac/InjuredAndroid

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

android android-security android-studio apk bug-bounty ctf flutter flutter-security flutter-xss kotlin kotlin-android pentesting security-testing vulnerabilities webview

Last synced: 08 Apr 2025

https://github.com/narstybits/macos-duckyscripts

Presenting a wide range of more than 100 powerful BadUSB scripts exclusively designed for Mac OS & the Flipper Zero device. As the sole curator and maintainer of this repository. Your utilization of these scripts is highly valued, and I sincerely appreciate your support and enthusiasm!

badusb badusb-payloads bash-script ducky-payloads duckyscript flipper flipper-zero flipperzero pentesting security-testing

Last synced: 27 Oct 2025

https://github.com/narstybits/MacOS-DuckyScripts

Presenting a wide range of more than 100 powerful BadUSB scripts exclusively designed for Mac OS & the Flipper Zero device. As the sole curator and maintainer of this repository. Your utilization of these scripts is highly valued, and I sincerely appreciate your support and enthusiasm!

badusb badusb-payloads bash-script ducky-payloads duckyscript flipper flipper-zero flipperzero pentesting security-testing

Last synced: 22 Feb 2025

https://github.com/sterrasec/apk-medit

memory search and patch tool on debuggable apk without root & ndk

android android-security arsenal blackhat mobile-app-security mobile-security-testing security-testing security-tools

Last synced: 31 Oct 2025

https://github.com/redcanaryco/chain-reactor

Chain Reactor is an open source framework for composing executables that simulate adversary behaviors and techniques on Linux endpoints.

adversary-simulation elf linux mitre mitre-attack security security-testing

Last synced: 16 May 2025

https://github.com/jjf012/gopoc

用cel-go重现了长亭xray的poc检测功能的轮子

poc proof-of-concept security-testing vulnerability-scanner

Last synced: 11 Jul 2025

https://github.com/trailofbits/siderophile

Find the ideal fuzz targets in a Rust codebase

fuzzing program-analysis rust security-testing

Last synced: 06 Oct 2025

https://github.com/tprynn/web-methodology

Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki

application-security appsec documentation security security-testing web web-application web-application-security

Last synced: 11 Jul 2025

https://github.com/openraven/magpie

A Cloud Security Posture Manager or CSPM with a focus on security analysis for the modern cloud stack and a focus on the emerging threat landscape such as cloud ransomware and supply chain attacks.

aws cloud cloudsecurity cspm gcp security security-audit security-scanner security-testing security-tools security-vulnerability

Last synced: 11 Jul 2025

https://github.com/paulveillard/cybersecurity

Welcome Cybersecurity's World. An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources in Cybersecurity.

computer-architecture computer-security cryptography cyber-physical-systems cybersecurity cybersecurity-awareness cybersecurity-blog cybersecurity-career-path cybersecurity-education cybersecurity-incidents defensive-security security security-audit security-automation security-hardening security-testing security-tools security-vulnerability

Last synced: 04 Apr 2025

https://github.com/sterrasec/ipa-medit

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

applesilicon arsenal blackhat ios ios-security m1 mobile-app-security mobile-security-testing security-testing security-tools

Last synced: 31 Oct 2025

https://github.com/syss-research/wirebug

WireBug is a toolset for Voice-over-IP penetration testing

hacking man-in-the-middle pentest rtp security security-testing sip sips srtp unified-communications vlan voip

Last synced: 21 Aug 2025

https://github.com/shnatsel/libdiffuzz

Custom memory allocator that helps discover reads from uninitialized memory

fuzz-testing fuzzing memory-allocator sanitizer security security-audit security-testing security-tools

Last synced: 16 Mar 2025

https://github.com/Shnatsel/libdiffuzz

Custom memory allocator that helps discover reads from uninitialized memory

fuzz-testing fuzzing memory-allocator sanitizer security security-audit security-testing security-tools

Last synced: 02 Apr 2025

https://github.com/circl/url-abuse

URL Abuse - A Versatile Software for URL review, analysis and black-list reporting

csirt-activities security-testing security-tools url-abuse

Last synced: 21 Jun 2025

https://github.com/falcosecurity/event-generator

Generate a variety of suspect actions that are detected by Falco rulesets

go kubernetes-auditing security security-testing syscall

Last synced: 05 Apr 2025

https://github.com/seungsoo-lee/DELTA

PROJECT DELTA: SDN SECURITY EVALUATION FRAMEWORK

pentesting sdn security-testing software-defined-networking

Last synced: 21 Nov 2025

https://github.com/seungsoo-lee/delta

PROJECT DELTA: SDN SECURITY EVALUATION FRAMEWORK

pentesting sdn security-testing software-defined-networking

Last synced: 04 Sep 2025

https://github.com/kpcyrd/boxxy-rs

Linkable sandbox explorer

regression-testing rust sandboxing security-testing

Last synced: 16 May 2025

https://github.com/Rektoff/Security-Roadmap-for-Solana-applications

We created a cybersecurity Systematization of Knowledge for Solana applications and protocols. We call it the Solana Security Strategy: such a database would be hugely beneficial for anyone who wants to secure their product and learn security from the best-collected resources.

blockchain-security rust security security-testing solana solana-program solana-security testing

Last synced: 25 Mar 2025

https://github.com/ciphermarco/BOAST

The BOAST Outpost for AppSec Testing: a server designed to receive and report Out-of-Band Application Security Testing (OAST) reactions.

appsec appsec-testing go golang security security-testing security-tools

Last synced: 10 May 2025

https://github.com/jay-johnson/owasp-jenkins

Want to test your applications using the latest OWASP security toolchains and the NIST National Vulnerability Database using Jenkins, Ansible and docker? :whale: :shield: :lock:

ansible c-sharp dependency-checker django docker jenkins national-vulnerability-database node nvd owasp python react ruby-on-rails security security-automation security-testing security-vulnerability tensorflow vue zap

Last synced: 06 Oct 2025

https://github.com/itboxltda/pentestlab

Script to manage and create local pentesting training virtual lab

cybersecurity cybersecurity-training-lab laboratory-automation owasp pentesting-resources security-testing

Last synced: 12 Jul 2025

https://github.com/frodox/execute-machine-code-from-memory

Proof of concept example: executing machine code from different memory areas: stack, heap, shared memory

c heap poc security security-testing shm stack

Last synced: 23 Aug 2025

https://github.com/vs4vijay/scanmaster

A security tool designed to perform thorough scans on a target using OpenVAS, Zap, and Nexpose. It seamlessly consolidates and integrates the scan results, providing a comprehensive overview of the security vulnerabilities identified.

application-security cli nexpose openvas openvas-cli openvas-reports owasp owasp-top owasp-zap security-audit security-scanner security-testing security-tools security-vulnerability web-application-security zap

Last synced: 29 Apr 2025

https://github.com/contrast-security-oss/safelog4j

Safelog4j is an instrumentation-based security tool to help teams discover, verify, and solve log4shell vulnerabilities without scanning or upgrading

iast java log4j log4shell rasp security security-testing vulnerability vulnerability-scanner

Last synced: 11 Sep 2025

https://github.com/Contrast-Security-OSS/safelog4j

Safelog4j is an instrumentation-based security tool to help teams discover, verify, and solve log4shell vulnerabilities without scanning or upgrading

iast java log4j log4shell rasp security security-testing vulnerability vulnerability-scanner

Last synced: 11 Jul 2025

https://github.com/paulveillard/cybersecurity-application-security

An ongoing & curated collection of awesome software practices and remediation, libraries and frameworks,payloads and techniques, best guidelines and technical resources about Application Security

application application-security appsec developer-security endpoint-security mdm-server mobilesecurity security-advisory security-hardening security-scanner security-testing security-tools security-vulnerability vulnerability-scanners web-security web-security-research

Last synced: 10 Apr 2025

https://github.com/Soluto/owasp-zap-glue-ci-images

Ready to use images of Zap and Glue, especially for CI integration.

ci docker-image owasp security-testing

Last synced: 11 May 2025

https://github.com/syss-research/lauschgeraet

Gets in the way of your victim's traffic and out of yours

802-1x mitm pentest security-testing security-tools tls traffic-analysis

Last synced: 10 Apr 2025

https://github.com/vectra-ai-research/Halberd

Cloud security testing tool to execute a comprehensive array of attack techniques across multiple surfaces via a simple web interface.

attack-defense aws azure azuread blueteam-tools cloud-security detection entra-id m365 microsoft mitre-attack offensive-security offensivesecurity redteam redteam-tools security-testing security-tools ttp

Last synced: 06 Mar 2025

https://github.com/gdgd009xcd/RequestRecorder

A ZAPROXY Add-on that allows testing of web application vulnerabilities by recording complex multi-step sequences. You can test applications that need to access pages in a specific order, such as shopping carts or registration of member information.

activescan addon authentication csrf multistep multistep-form security security-testing security-tools vulnerability-scanners web-security webcrawler websecurity zap-extension zaproxy

Last synced: 31 Oct 2025

https://github.com/wakeful/veil

Verified Entity Identity Lock (Expose hidden trust paths in your AWS IAM setup before they become security risks.)

aws blue blue-team blue-team-tool blueteam blueteam-tools cybersecurity penetration-testing recon security security-auditing security-automation security-testing security-tools

Last synced: 04 Sep 2025

https://github.com/das-group/rba-dataset

Login feature data of more than 33M login attempts and 3M users (IP, UA, RTT)

authentication data-set ip-address login-data risk-based-authentication round-trip-time security-testing user-agent

Last synced: 26 Feb 2025

https://github.com/benmccallum/blip

Test business websites for speed, usability, security and the HTML5 doctype in a neighbourhood or by URL.

automated-testing performance-testing security-testing testing testing-tools usability-testing

Last synced: 11 Mar 2025

https://github.com/thomashartm/burp-domsink-logger

Injects a trusted types policy into an HTML page to log all DOM sinks whenever HTML is written into the DOM.

burp burp-extensions burp-plugin burpsuite-extender cross-site-scripting domxss java javascript penetration-testing-tools security-testing security-tools trusted-types

Last synced: 23 Mar 2025

https://github.com/karma9874/authinspector

Automated authorization checks with multiple headers tool written in golang

authorization bug-bounty golang privilege-escalation security-scanner security-testing security-tools

Last synced: 24 Jul 2025

https://github.com/omerlh/container-security-testing

A list of security testing tools for containerized applications

appsec cicd containers devsecops docker kubernetes security-testing

Last synced: 11 Oct 2025

https://github.com/lamsut/ths2024-77

PHP web application for Information Security education, utilizing OpenStack for security testing practices

ctf-challenges information-security mysql openstack php security-testing

Last synced: 14 Apr 2025

https://github.com/lamsut/w0rm

PHP web application for Information Security education, utilizing OpenStack for security testing practices

ctf-challenges information-security openstack php security-testing

Last synced: 13 Sep 2025

https://github.com/hcl-tech-software/appscan-sast-action

Integrate static security testing with HCL AppScan on Cloud using GitHub Actions

action appscan github github-actions sast scanning security security-automation security-scanner security-testing security-tools

Last synced: 31 Aug 2025

https://github.com/jul10l1r4/identificador-cve-2018-11759

This exploit for CVE 2018-11759, vulnerability in apache mod_jk, module for load-balancer

apache2 cve cve-2018-11759 load-balancer module protection safe security security-testing

Last synced: 16 May 2025

https://github.com/geniuszly/GenProxyJSChecker

is a Node.js tool designed to validate the functionality of various types of proxy servers, including HTTP, HTTPS, SOCKS4, and SOCKS5. It reads a list of proxies from a file, checks each proxy's connectivity using the specified protocol, and logs the results.

automation checker cybersecurity ethical-hacking genproxyjschecker javascript js network-security network-tools nodejs penetration-testing proxy proxy-checker proxy-detection security-testing web-security

Last synced: 07 May 2025