Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

Cybersecurity

Cybersecurity involves protecting systems, networks, and data from cyber threats. This field encompasses a wide range of practices and technologies designed to safeguard information from unauthorized access, attacks, damage, or theft. Cybersecurity includes preventive measures such as firewalls, encryption, and secure coding practices, as well as detection and response strategies like intrusion detection systems and incident response plans. This topic covers the principles, best practices, and latest trends in cybersecurity, including emerging threats and the evolving landscape of cyber defense.

https://github.com/OpenBAS-Platform/openbas

Open Breach and Attack Simulation Platform

attack-simulation breach-simulator cybersecurity purple-team

Last synced: 09 Dec 2024

https://github.com/mergebase/log4j-detector

A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too! TAG_OS_TOOL, OWNER_KELLY, DC_PUBLIC

cve-2021-44228 cve-2021-45046 cve-2021-45105 cybersecurity detector log4j log4shell pentest sca scanner vulnerability-scanner

Last synced: 20 Nov 2024

https://github.com/hideckies/exploit-notes

Sticky notes for pentesting, bug bounty, CTF.

cybersecurity hacking-tools pentesting

Last synced: 12 Nov 2024

https://github.com/counteractive/incident-response-plan-template

A concise, directive, specific, flexible, and free incident response plan template

cybersecurity incident incident-management incident-response information-security infosec

Last synced: 03 Nov 2024

https://github.com/maid233/pybitcracker

PyBitCracker Python-Bitcoin-Cracker BTC-Private-Key Crypto-Wallet-Recovery Bitcoin-Password-Cracker Blockchain-Security BTC-Recovery-Tool Python-Crypto-Tool Wallet-Security Cryptocurrency-Tool BTC-Cracking

bitcoin-password-cracker bitcoin-tool blockchain-security blockchain-tool btc-cracking btc-key-recovery btc-private-key btc-recovery-tool crypto-recovery crypto-wallet-recovery cryptocurrency-tool cybersecurity digital-wallet-cracker ethical-hacking private-key-tool pybitcracker python-bitcoin-cracker python-crypto-tool python-wallet-tool wallet-security

Last synced: 16 Jan 2025

https://github.com/msuiche/OPCDE

OPCDE Cybersecurity Conference Materials

cybersecurity incident-response information-security vulnerability

Last synced: 03 Nov 2024

https://github.com/bluecapesecurity/PWF

Practical Windows Forensics Training

blueteam cybersecurity forensics purpleteam

Last synced: 21 Nov 2024

https://github.com/cyberark/pipeviewer

A tool that shows detailed information about named pipes in Windows

blueteam cybersecurity namedpipe namedpipes redteam redteam-tools research-tool windows

Last synced: 18 Jan 2025

https://github.com/idov31/cronos

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

assembly c cyber-security cybersecurity encryption evasion infosec red-team redteam windows

Last synced: 18 Jan 2025

https://github.com/RhinoSecurityLabs/ccat

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

amazon aws ccat cloud cybersecurity docker ecr eks gce gcp gke google k8s kubernetes pentest pentesting rhino rhinosecuritylabs

Last synced: 11 Nov 2024

https://github.com/rhinosecuritylabs/ccat

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

amazon aws ccat cloud cybersecurity docker ecr eks gce gcp gke google k8s kubernetes pentest pentesting rhino rhinosecuritylabs

Last synced: 19 Jan 2025

https://github.com/BushidoUK/Open-source-tools-for-CTI

Public Repository of Open Source Tools for Cyber Threat Intelligence Analysts and Researchers

cti cybersecurity infosec malware osint threatintel

Last synced: 19 Nov 2024

https://github.com/center-for-threat-informed-defense/attack-flow

Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by developing a representation of attack flows, modeling attack flows for a small corpus of incidents, and creating visualization tools to display attack flows.

ctid cyber-threat-intelligence cybersecurity mitre-attack threat-informed-defense

Last synced: 17 Jan 2025

https://github.com/wgpsec/lc

LC(List Cloud)是一个多云攻击面资产梳理工具

cloud cloudsecurity cybersecurity

Last synced: 20 Jan 2025

https://github.com/MetaOSINT/MetaOSINT.github.io

A tool to quickly identify relevant, publicly-available open source intelligence ("OSINT") tools and resources, saving valuable time during investigations, research, and analysis.

cryptocurrency cybersecurity disinformation email facebook geoint geolocation instagram intelligence investigation news opsec osint search search-engine security social-media social-network twitter username

Last synced: 09 Dec 2024

https://github.com/infobyte/emploleaks

An OSINT tool that helps detect members of a company with leaked credentials

bugbounty cybersecurity leaked-secrets osint pentesting redteam

Last synced: 19 Jan 2025

https://github.com/the-xentropy/samlists

Free, libre, effective, and data-driven wordlists for all!

bugbounty cybersecurity hacking hacking-tools

Last synced: 29 Oct 2024

https://github.com/escape-technologies/graphql-armor

🛡️ The missing GraphQL security security layer for Apollo GraphQL and Yoga / Envelop servers 🛡️

apollo apollo-server cybersecurity envelop graphql hacktoberfest middleware security security-tools typescript

Last synced: 15 Jan 2025

https://github.com/Escape-Technologies/graphql-armor

🛡️ The missing GraphQL security security layer for Apollo GraphQL and Yoga / Envelop servers 🛡️

apollo apollo-server cybersecurity envelop graphql hacktoberfest middleware security security-tools typescript

Last synced: 13 Nov 2024

https://github.com/trimstray/otseca

Open source security auditing tool to search and dump system configuration. It allows you to generate reports in HTML or RAW-HTML formats.

auditing cybersecurity dump html-report information-gathering linux pentesting reporting security-audit security-tools system system-analysis system-config system-information

Last synced: 19 Jan 2025

https://github.com/knight0x07/ImpulsiveDLLHijack

C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be weaponized during Red Team Operations to evade EDR's.

cybersecurity dll-hijacking redteam redteam-tools

Last synced: 01 Nov 2024

https://github.com/kleiton0x00/ppmap

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

bug-bounty bugbounty bugbounty-tool cybersecurity infosec prototype-pollution xss xss-detection xss-exploitation xss-vulnerability

Last synced: 20 Jan 2025

https://github.com/azure/security-copilot

Microsoft Security Copilot is a generative AI-powered security solution that helps increase the efficiency and capabilities of defenders to improve security outcomes at machine speed and scale, while remaining compliant to responsible AI principles

cybersecurity generativeai largelanguagemodel logicapps sample-code

Last synced: 18 Jan 2025

https://github.com/cipher387/linux-for-osint-21-day

In this repository you will find sample commands and test files for each day of the course "Linux for OSINT. A 21-day course for beginners".

bash cybersecurity linux osint shell

Last synced: 19 Jan 2025

https://github.com/pwnfoo/ntlmrecon

Enumerate information from NTLM authentication enabled web endpoints 🔎

blackarch cybersecurity enumeration hacking hacking-tools ntlm ntlmssp osint recon reconnaissance redteam security tools

Last synced: 22 Jan 2025

https://github.com/daniel-cues/NMapGUI

Advanced Graphical User Interface for NMap

cybersecurity monitoring network-analysis nmap security sysadmin

Last synced: 03 Nov 2024

https://github.com/pwnfoo/NTLMRecon

Enumerate information from NTLM authentication enabled web endpoints 🔎

blackarch cybersecurity enumeration hacking hacking-tools ntlm ntlmssp osint recon reconnaissance redteam security tools

Last synced: 21 Nov 2024

https://github.com/center-for-threat-informed-defense/tram

TRAM is an open-source platform designed to advance research into automating the mapping of cyber threat intelligence reports to MITRE ATT&CK®.

ctid cyber-threat-intelligence cybersecurity mitre-attack threat-informed-defense

Last synced: 18 Jan 2025

https://github.com/diogo-fernan/ir-rescue

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

bash batch cybersecurity dfir forensics incident-response malware nirsoft sysinternals unix windows

Last synced: 03 Nov 2024

https://github.com/idnahacks/goodhound

Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.

active-directory activedirectory bloodhound blueteam cybersecurity neo4j purpleteam py2neo python python3 redteam

Last synced: 17 Jan 2025

https://github.com/infosecb/loobins

Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in "living off the land" macOS binaries and how they can be used by threat actors for malicious purposes.

blueteam cybersecurity detection dfir living-off-the-land loobins macos redteam

Last synced: 21 Jan 2025

https://github.com/austin-taylor/flare

An analytical framework for network traffic and behavioral analytics

analytics cybersecurity domains elasticsearch network-analysis python

Last synced: 20 Jan 2025

https://github.com/azure/copilot-for-security

Microsoft Copilot for Security is a generative AI-powered security solution that helps increase the efficiency and capabilities of defenders to improve security outcomes at machine speed and scale, while remaining compliant to responsible AI principles

cybersecurity generativeai largelanguagemodel logicapps sample-code

Last synced: 07 Oct 2024

https://github.com/mohitmishra786/reversingbits

A comprehensive collection of cheatsheets for reverse engineering, binary analysis, and assembly programming tools. This repository serves as a one-stop reference for security researchers, reverse engineers, and low-level programmers.

assembly binary-analysis binary-exploitation ctf-tools cybersecurity cybersecurity-tools debugging disassembly dynamic-analysis malware-analysis penetration-testing program-analysis reverse-engineering reversing security-tools static-analysis system-security vulnerability-research x86-64 x86-assembly

Last synced: 18 Jan 2025

https://github.com/cmu-sei/ghosts

GHOSTS is a realistic user simulation framework for cyber simulation, training, and exercise

behavior cyber cybersecurity cybertraining exercise human network-simulation network-simulations network-simulator simulation simulation-modeling training user-simulator

Last synced: 18 Jan 2025

https://github.com/yaklang/yaklang

A programming language exclusively designed for cybersecurity

cybersecurity dsl go security security-tools

Last synced: 18 Jan 2025

https://github.com/simplerhacking/Evilginx3-Phishlets

This repository provides penetration testers and red teams with an extensive collection of dynamic phishing templates designed specifically for use with Evilginx3. May be updated periodically.

ai cybersecurity evilginx2 evilginx3 gophish infosec kali-linux pentesting phishing phishlets python redteaming script

Last synced: 02 Jan 2025

https://github.com/OWASP/Python-Honeypot

OWASP Honeypot, Automated Deception Framework.

cybersecurity deception honeynet honeypot informationsecurity infosec owasp security

Last synced: 02 Nov 2024

https://github.com/gacwr/openuba

A robust, and flexible open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by Data Scientists & Security Analysts from the Cyber Security Industry. [PRE-ALPHA]

analytics anomaly-detection cybersecurity datascience elasticsearch elk flask information-security machine-learning nodejs react security siem sklearn spark tensorflow threathunting uba ueba user-behaviour

Last synced: 17 Jan 2025

https://github.com/theahmadov/NIVOS

NIVOS is a hacking tool that allows you to scan deeply , crack wifi, see people on your network. It applies to all linux operating systems. And it is improving every day, new packages are added. Thank You For Using NIVOS :> [NIVOS Created By NIVO Team]

azerbaijan azerbaycan bash brute-force coding cyber-security cybersecurity hack hacker hacking hacking-tools linux penetration-testing python tools turkey wifi

Last synced: 25 Nov 2024

https://github.com/redhuntlabs/bucketloot

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text.

automation blackhat bounty bugbounty bughunting cli cloud cloud-security cybersecurity infosec infosectools osint pentesting recon reconnaissance s3 secret-scanning

Last synced: 19 Jan 2025

https://github.com/CERT-Polska/karton

Distributed malware processing framework based on Python, Redis and S3.

cert csirt cybersecurity karton malware-analysis malware-research pipeline

Last synced: 09 Nov 2024

https://github.com/spectralops/netz

Discover internet-wide misconfigurations while drinking coffee

cybersecurity go golang osint scanner

Last synced: 21 Jan 2025

https://github.com/ANG13T/skytrack

skytrack is a planespotting and aircraft OSINT tool made using Python 🛩🔍

aerospace aircraft aviation cybersecurity cybersecurity-tools osint planes planespotting python reconnaissance

Last synced: 18 Nov 2024

https://github.com/SpectralOps/netz

Discover internet-wide misconfigurations while drinking coffee

cybersecurity go golang osint scanner

Last synced: 30 Nov 2024

https://github.com/SitinCloud/Owlyshield

Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact).

antivirus behavior-analysis command-and-control cybersecurity edr exfiltration impact machine-learning malware malware-analysis malware-research ransomware threat-hunting

Last synced: 24 Nov 2024

https://github.com/Fortiphyd/GRFICSv2

Version 2 of the Graphical Realism Framework for Industrial Control Simulation (GRFICS)

cybersecurity hmi ics-security industrial-automation plc-programming

Last synced: 21 Nov 2024

https://github.com/idov31/venom

Venom is a library that meant to perform evasive communication using stolen browser socket

backdoor cpp cyber cyber-security cybersecurity infosec red-team red-team-tools redteam windows

Last synced: 20 Jan 2025

https://github.com/humblelad/Shodan-Dorks

Dorks for shodan.io. Some basic shodan dorks collected from publicly available data.

cybersecurity hacking pentest shodan shodan-dorks

Last synced: 17 Nov 2024

https://github.com/Idov31/Venom

Venom is a library that meant to perform evasive communication using stolen browser socket

backdoor cpp cyber cyber-security cybersecurity infosec red-team red-team-tools redteam windows

Last synced: 09 Nov 2024

https://github.com/curtbraz/PhishAPI

Comprehensive Web Based Phishing Suite for Rapid Deployment and Real-Time Alerting!

cyberaware cybersecurity hacking infosec pentesting phish phishing phishing-kit security socialengineering

Last synced: 21 Nov 2024

https://github.com/diogo-fernan/malsub

A Python RESTful API framework for online malware analysis and threat intelligence services.

api-client cybersecurity malware malware-analysis python restful restful-client virustotal

Last synced: 03 Nov 2024

https://github.com/cisagov/crossfeed

External monitoring for organization assets

cybersecurity infrastructure scanning

Last synced: 27 Dec 2024

https://github.com/redhuntlabs/BucketLoot

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text.

automation blackhat bounty bugbounty bughunting cli cloud cloud-security cybersecurity infosec infosectools osint pentesting recon reconnaissance s3 secret-scanning

Last synced: 02 Jan 2025

https://github.com/idaholab/Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

arkime cybersecurity infosec network-security network-traffic-analysis networksecurity networktrafficanalysis opensearch opensearch-dashboards pcap security suricata zeek

Last synced: 01 Nov 2024

https://github.com/idaholab/malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

arkime cybersecurity infosec network-security network-traffic-analysis networksecurity networktrafficanalysis opensearch opensearch-dashboards pcap security suricata zeek

Last synced: 24 Oct 2024

https://github.com/elliotkillick/qvm-create-windows-qube

Spin up new Windows qubes quickly, effortlessly and securely on Qubes OS

automation cybersecurity infosec privacy qubes qubes-os security virtualization whonix windows windows-10

Last synced: 20 Jan 2025

https://github.com/volkandindar/agartha

A Burp extension helps identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations, while also converting HTTP requests to JavaScript for enhanced XSS exploitation.

application-security appsec burp-extensions burpsuite cybersecurity hacking hacking-tool offensivesecurity offsec penetration-testing pentesting

Last synced: 18 Nov 2024

https://github.com/Skiller9090/Lucifer

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build Automation Modules To Speed Up Your Cyber Security Life

automation automation-framework cyber-security cybersec cybersecurity enumeration exfiltration framework hacking hacking-framework hacking-tool modular modules pentest-tool pentesting privilege-escalation python security security-tools

Last synced: 21 Nov 2024

https://github.com/ElliotKillick/qvm-create-windows-qube

Spin up new Windows qubes quickly, effortlessly and securely on Qubes OS

automation cybersecurity infosec privacy qubes qubes-os security virtualization whonix windows windows-10

Last synced: 06 Nov 2024

https://github.com/tarraschk/richelieu

List of the most common French passwords

audit bruteforce-wordlist cybersecurity dictionary security

Last synced: 18 Nov 2024

https://github.com/spellshift/realm

Realm is a cross platform Red Team engagement platform with a focus on automation and reliability.

agent bot c2 cyber cybersecurity golang graphql implant react redteam redteam-tools redteaming rust teamserver typescript webui

Last synced: 05 Nov 2024

https://github.com/aabysszg/docker-tcp-scan

旨在以攻促防,针对Docker TCP socket的开源利用工具

cloud-security cybersecurity cybersecurity-education docker docker-remote-api rce

Last synced: 20 Jan 2025

https://github.com/montysecurity/C2-Tracker

Live Feed of C2 servers, tools, and botnets

cybersecurity infosec osint shodan threat-hunting threat-intelligence

Last synced: 06 Nov 2024

https://github.com/Puliczek/CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera

🎩 🤟🏻 [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak - CVE-2022-0337

bugbounty bugbounty-writeups bugbountytips cve cve-2022-0337 cybersecurity exploit hacking payload pentest pentesting red-team security security-writeups writeups

Last synced: 03 Nov 2024

https://github.com/intigriti/misconfig-mapper

Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!

bug-bounty bugbounty cybersecurity hacking hacking-tool misconfig misfconfiguration services

Last synced: 23 Oct 2024