An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/t94j0/AIRMASTER

Use ExpiredDomains.net and BlueCoat to find useful domains for red team.

engagements pentest-tool pentesting red-team security security-tools

Last synced: 03 Oct 2025

https://github.com/kreuzwerker/awsu

Enhanced account switching for AWS, supports Yubikey as MFA source

aws golang hacktoberfest mfa security yubikey

Last synced: 04 Jan 2026

https://github.com/raspbernetes/k8s-security-policies

This repository offers a comprehensive library of security policies designed to enhance the security of Kubernetes cluster configurations. The policies are developed in accordance with the CIS Kubernetes benchmark.

benchmark cis cis-kubernetes-benchmark conftest gatekeeper kubernetes kubernetes-clusters kubesec open-policy-agent raspbernetes rego-files rego-policy security violation

Last synced: 12 May 2025

https://github.com/cynicsketch/nix-mineral

Conveniently and reasonably harden NixOS.

nix nixos privacy security

Last synced: 29 Dec 2025

https://github.com/SecAegis/SecReport

ChatGPT加持的,多人在线协同信息安全报告编写平台。目前支持的报告类型:渗透测试报告,APP隐私合规报告。

ai chatgpt collaboration collaborations docker openai pentest privacy rce report retest sec security security-tools sql-injection vulnerabilities web-security xss

Last synced: 07 Sep 2025

https://github.com/shubhampathak/autosetup

Auto setup is a bash script compatible with Debian based distributions to install and setup necessary programs.

autoinstall autosetup bash bugbounty debian infosec kali-linux linux post-installation postinstall recon reconnaissance script security shell ubuntu ubuntu-installation

Last synced: 12 Jul 2025

https://github.com/t94j0/airmaster

Use ExpiredDomains.net and BlueCoat to find useful domains for red team.

engagements pentest-tool pentesting red-team security security-tools

Last synced: 21 Aug 2025

https://github.com/vmware/secrets-manager

VMware Secrets Manager is a lightweight secrets manager to protect your sensitive data. It’s perfect for edge deployments where energy and footprint requirements are strict—See more: https://vsecm.com/

cloud-native edge kubernetes secret-management secrets-manager security spiffe spire zero-trust

Last synced: 05 Oct 2025

https://github.com/secaegis/secreport

ChatGPT加持的,多人在线协同信息安全报告编写平台。目前支持的报告类型:渗透测试报告,APP隐私合规报告。

ai chatgpt collaboration collaborations docker openai pentest privacy rce report retest sec security security-tools sql-injection vulnerabilities web-security xss

Last synced: 11 Jun 2025

https://github.com/gehaxelt/phuzz

Modular & Open-Source Coverage-Guided Web Application Fuzzer for PHP

fuzzing fuzzing-paper php security security-tools

Last synced: 05 Oct 2025

https://github.com/horlogeskynet/thunderbird-user.js

Thunderbird privacy, security and anti-fingerprinting: a comprehensive user.js template for configuration and hardening

anti-fingerprinting arkenfox email ghacks privacy security thunderbird user-js

Last synced: 04 Apr 2025

https://github.com/flavienbwk/opensearch-docker-compose

Dockerized cluster architecture for OpenSearch with compose.

cluster docker docker-compose elasticsearch opendistro opensearch security

Last synced: 12 Apr 2025

https://github.com/riolet/SAM

System Architecture Mapper

analysis diagnostics networking security system-architecture

Last synced: 09 Apr 2025

https://github.com/VbScrub/Rubeus-GUI

GUI alternative to the Rubeus command line tool, for all your Kerberos exploit requirements

activedirectory kerberos security

Last synced: 11 Jul 2025

https://github.com/cyberagiinc/DevDocs

Completely free, private, intuitive UI based Web Scraping MCP server. Designed for coders and software developers in mind. Easily integrate into Cursor, Windsurf, Cline, Roo Code, Claude Desktop App

cline crawl4ai cursor documentation llm playwright python3 scraper security typescript windsurf

Last synced: 06 Mar 2025

https://github.com/HorlogeSkynet/thunderbird-user.js

Thunderbird privacy, security and anti-fingerprinting: a comprehensive user.js template for configuration and hardening

anti-fingerprinting arkenfox email ghacks privacy security thunderbird user-js

Last synced: 27 Mar 2025

https://github.com/ManuelBerrueta/FlowAnalyzer

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

appsec identity oauth oauth2 oidc openid openid-connect redteam security security-tools

Last synced: 03 Apr 2025

https://github.com/sec-report/secreport

ChatGPT加持的,多人在线协同信息安全报告编写平台。目前支持的报告类型:渗透测试报告,APP隐私合规报告。

ai chatgpt collaboration collaborations docker openai pentest privacy rce report retest sec security security-tools sql-injection vulnerabilities web-security xss

Last synced: 05 Apr 2025

https://github.com/mikropsoft/StevenBlock

🚫 Advanced Ad-Blocking Module for Android | Compatible with Magisk, KernelSU, and APatch 🔒

ad-block adblock adblocker android apatch block-ads content-blocker dns firewall hosts kernelsu magisk magisk-module modules network privacy root security stevenblack systemless

Last synced: 15 Jul 2025

https://github.com/google/node-sec-roadmap

Some thoughts on how Node.js might respond to a changing security environment

gitbook nodejs security

Last synced: 01 Apr 2025

https://github.com/anders/pwgen

macOS password generator

objective-c password password-generator pwgen security

Last synced: 22 Aug 2025

https://github.com/federicoceratto/bottle-cork

Authentication module for the Bottle and Flask web frameworks

authentication authorization bottle flask http python python2 python3 security web

Last synced: 06 Apr 2025

https://github.com/mukeshsolanki/android-tamper-detector

A simple library that can help you detect if you app is modded or tampered with

android hack-detection libraries modded security tamper-detector

Last synced: 19 Apr 2025

https://github.com/netflix/lemur-docker

Docker files for the Lemur certificate orchestration tool

security

Last synced: 24 Oct 2025

https://github.com/actions-rs/audit-check

🛡️ GitHub Action for security audits

advisory audit cargo github rust rust-lang rustsec security vulnerability

Last synced: 16 May 2025

https://github.com/eylandoo/openvpn_webpanel_manager

A powerful, self-hosted web panel for managing OpenVPN servers, users, resellers (sub-admins), and multi-node deployments with a feature-rich UI and full API support.

cisco eylan eylanpanel ipsec l2tp multi-node openvpn openvpn-management reseller-panel security self-hosted user-management vpn vpn-manager vpn-panel vpn-server

Last synced: 03 Feb 2026

https://github.com/Netflix/lemur-docker

Docker files for the Lemur certificate orchestration tool

security

Last synced: 07 May 2025

https://github.com/cloudposse/terraform-aws-ec2-instance

Terraform module for provisioning a general purpose EC2 host

ansible aws ec2 hcl2 instance security terraform terraform-modules

Last synced: 08 Apr 2025

https://github.com/dsgnr/portchecker.io

portchecker.io is a free online utility to check the port status of a given hostname or IP address.

check docker litestar port react security self-hosted

Last synced: 16 Jan 2026

https://github.com/netflix/bettertls

BetterTLS: A Name Constraints test suite for HTTPS clients.

security

Last synced: 01 Jul 2025

https://github.com/opsxcq/docker-tor-hiddenservice-nginx

Easily setup a hidden service inside the Tor network

anonimity docker hidden hidden-services privacy security tor tor-network

Last synced: 19 Mar 2025

https://github.com/syss-research/wirebug

WireBug is a toolset for Voice-over-IP penetration testing

hacking man-in-the-middle pentest rtp security security-testing sip sips srtp unified-communications vlan voip

Last synced: 21 Aug 2025

https://github.com/simeononsecurity/standalone-windows-stig-script

Create a compliant and secure Windows 10/11 system with our Gold Master image creation tool. Adhere to DoD STIG/SRG Requirements and NSA Cybersecurity guidance for standalone Windows systems with ease, using our ultimate STIG script.

automation compliance cyber enterprise hardening hardware-requirements microsoft mil nsacyber powershell protection security security-hardening srgs-applied standalone-systems stig stigs windows windows10

Last synced: 11 May 2025

https://github.com/stanford-esrg/lzr

LZR quickly detects and fingerprints unexpected services running on unexpected ports.

go golang internet-wide-scanning ipv4 network port-scan port-scanner port-scanning scanning security security-tools zgrab zmap

Last synced: 04 Apr 2025

https://github.com/drduh/pc-engines-apu-router-guide

Guide to building a Linux or BSD router on the PC Engines APU platform

debian firewall home-network home-security homelab iptables linux openbsd pcengines privacy router security vpn walkthrough

Last synced: 26 Mar 2025

https://github.com/thebabush/dumb-obfuscator

Tutorial on how to write the dumbest obfuscator I could think of.

clang encryption llvm llvm-pass llvm-tutorial obfuscation security tutorial

Last synced: 16 Jan 2026

https://github.com/jgamblin/blackhat-macos-config

Configure Your Macbook For Blackhat

blackhat macos-setup security

Last synced: 04 Jul 2025

https://github.com/jgamblin/Blackhat-MacOS-Config

Configure Your Macbook For Blackhat

blackhat macos-setup security

Last synced: 03 Oct 2025

https://github.com/xsa/infosec-events

List of past and future infosec related events.

conferences cybersecurity events infosec security

Last synced: 27 Jan 2026

https://github.com/mschwager/0wned

Code execution via Python package installation.

code-execution package-installation pip python python-package remote-code-execution security

Last synced: 10 Apr 2025

https://github.com/jakiboy/revens

Windows-based Reverse Engineering Toolkit "All-In-One", Built for Security (Malware analysis, Penetration testing) & Educational purposes.

awesome-re malware-analysis penetration-testing reverse-engineering security

Last synced: 21 Jun 2025

https://github.com/gabrielsoltz/metahub

MetaHub is an automated contextual security findings enrichment and impact evaluation tool for vulnerability management.

asff aws security securityhub

Last synced: 31 Mar 2025

https://github.com/tintinweb/striptls

proxy poc implementation of STARTTLS stripping attacks

interception man-in-the-middle mitm security security-audit starttls striptls tcp-proxy tls

Last synced: 03 Sep 2025

https://github.com/aliasrobotics/RVD

Robot Vulnerability Database. An archive of robot vulnerabilities and bugs.

bounty bug cybersecurity drones flaw hacking px4 robot robot-vulnerabilities robotics robots ros ros2 security vulnerability vulns-ros2

Last synced: 23 Apr 2025

https://github.com/p4t12ick/ypsilon

Automated Use Case Testing

ansible cuckoo elk malware security siem splunk use-case

Last synced: 12 Apr 2025

https://github.com/XRSec/AWVS-Update

Awvs Scanner、fahai

security

Last synced: 11 Jul 2025

https://github.com/michenriksen/searchpass

A simple tool for offline searching of default credentials for network devices, web applications and more.

passwords ruby ruby-cli security

Last synced: 09 Apr 2025

https://github.com/doudoudedi/hackembedded

This tool is used for backdoor,shellcode generation,Information retrieval and POC arrangement for various architecture devices

cve exploit iot linux poc python reverse-shell security

Last synced: 06 Apr 2025

https://github.com/P4T12ICK/ypsilon

Automated Use Case Testing

ansible cuckoo elk malware security siem splunk use-case

Last synced: 09 May 2025

https://github.com/googlecloudplatform/gke-rbac-demo

This project covers two use cases for RBAC within a Kubernetes Engine cluster. First, assigning different permissions to user personas. Second, granting limited API access to an application running within your cluster. Since RBAC's flexibility can occasionally result in complex rules, you will also perform common steps for troubleshooting RBAC as a part of the second scenario.

gke gke-helmsman google-cloud-platform kubernetes kubernetes-engine rbac security

Last synced: 16 Sep 2025

https://github.com/dlint-py/dlint

Dlint is a tool for encouraging best coding practices and helping ensure Python code is secure.

dlint flake8 linter python security static-analysis

Last synced: 21 Oct 2025

https://github.com/puliczek/cve-2021-21123-poc-google-chrome

🐱‍💻 👍 Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123 and 5 more...

bugbounty bugbounty-writeups bugbountytips cve cybersecurity exploit hacking payload pentesing pentest red-team security security-writeups writeups

Last synced: 15 Oct 2025

https://github.com/moloch--/CSP-Bypass

A Burp Plugin for Detecting Weaknesses in Content Security Policies

burp-plugin content-security-policy csp security

Last synced: 19 Apr 2025

https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome

🐱‍💻 👍 Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123 and 5 more...

bugbounty bugbounty-writeups bugbountytips cve cybersecurity exploit hacking payload pentesing pentest red-team security security-writeups writeups

Last synced: 02 Apr 2025

https://github.com/wortell/KQL

KQL queries for Advanced Hunting

hunting kql security

Last synced: 11 May 2025

https://github.com/tinyhttp/malibu

🏄 Framework-agnostic CSRF middleware for modern Node.js

csrf esm http middleware nodejs security session tinyhttp

Last synced: 07 Sep 2025

https://github.com/Netflix/bettertls

BetterTLS: A Name Constraints test suite for HTTPS clients.

security

Last synced: 01 Apr 2025

https://github.com/poddmo/ufw-blocklist

IP blocklist extension for Ubuntu ufw firewall

firewall ip-blocklist ipset linux network network-security security ubuntu ufw

Last synced: 30 Jan 2026

https://github.com/sensepost/routopsy

Routopsy - Hacking Routers with Routers

network pentest security

Last synced: 26 Oct 2025

https://github.com/BobNisco/adblocking-vpn

🔒 Create your own VPN server that blocks malicious domains to enhance your security and privacy

adblock dnsmasq linux openvpn privacy security vpn vpn-server

Last synced: 27 Mar 2025

https://github.com/stanford-esrg/retina

Retina is a network analysis framework that supports 100+ Gbps traffic analysis on a single server with no specialized hardware.

analysis dpdk network rust security

Last synced: 04 Apr 2025

https://github.com/openbsm/openbsm

OpenBSM open audit implementation

audit bsm freebsd linux logging osx security

Last synced: 06 Feb 2026

https://github.com/simeononsecurity/Standalone-Windows-STIG-Script

Create a compliant and secure Windows 10/11 system with our Gold Master image creation tool. Adhere to DoD STIG/SRG Requirements and NSA Cybersecurity guidance for standalone Windows systems with ease, using our ultimate STIG script.

automation compliance cyber enterprise hardening hardware-requirements microsoft mil nsacyber powershell protection security security-hardening srgs-applied standalone-systems stig stigs windows windows10

Last synced: 09 Apr 2025

https://github.com/xiaomingx/data-cve-poc

这个仓库收集了所有在 GitHub 上能找到的 CVE 漏洞利用工具。 This repository collects all CVE exploits found on GitHub.

cve exp poc rpc security vulnerability

Last synced: 05 Apr 2025

https://github.com/bobnisco/adblocking-vpn

🔒 Create your own VPN server that blocks malicious domains to enhance your security and privacy

adblock dnsmasq linux openvpn privacy security vpn vpn-server

Last synced: 09 Jul 2025

https://github.com/umair9747/Genzai

The IoT security toolkit to help identify IoT related dashboards and scan them for default passwords and vulnerabilities.

cybersecurity golang hacking iot iot-security penetration-testing pentesting redteam security security-scanner security-tools

Last synced: 27 Sep 2025

https://github.com/mytechnotalent/turbo-scanner

A port scanner and service detection tool that uses 1000 goroutines at once to scan any hosts IP or FQDN with the sole purpose of testing your own network to ensure there are no malicious services running.

blue-team blue-teams cyber cybersecurity defensive-security go golang malware malware-analysis port-scanner portscanner russia russian security security-tools tcp tcp-scanner tor ukraine

Last synced: 14 Jan 2026

https://github.com/panagiotisdrakatos/springboot-registration-login-theperfectexample

Login & Signup tutorial for every website ,mixes a lot of microservices together with the latest spring framework api in combined with full security

authentication dao-interface jpa microservice mysql security spring-boot spring-data spring-framework spring-security spring-session

Last synced: 08 May 2025

https://github.com/PanagiotisDrakatos/SpringBoot-Registration-Login-ThePerfectExample

Login & Signup tutorial for every website ,mixes a lot of microservices together with the latest spring framework api in combined with full security

authentication dao-interface jpa microservice mysql security spring-boot spring-data spring-framework spring-security spring-session

Last synced: 09 May 2025

https://github.com/edoverflow/proof-of-concepts

A little collection of fun and creative proof of concepts to demonstrate the potential impact of a security vulnerability.

bugbounty infosec poc proof-of-concept security

Last synced: 13 May 2025

https://github.com/moloch--/csp-bypass

A Burp Plugin for Detecting Weaknesses in Content Security Policies

burp-plugin content-security-policy csp security

Last synced: 20 Aug 2025

https://github.com/digitalis-io/vals-operator

Kubernetes Operator to sync secrets between different secret backends and Kubernetes

devops devsecops kubernetes kubernetes-operator secrets secrets-management security vals

Last synced: 19 Jan 2026

https://github.com/k0retux/fuddly

Fuzzing and Data Manipulation Framework (for GNU/Linux)

data-manipulation framework fuzzing python security

Last synced: 20 Apr 2025

https://github.com/shnatsel/libdiffuzz

Custom memory allocator that helps discover reads from uninitialized memory

fuzz-testing fuzzing memory-allocator sanitizer security security-audit security-testing security-tools

Last synced: 16 Mar 2025

https://github.com/sigstore/sigstore-js

Code-signing for npm packages

codesigning javascript node security supply-chain

Last synced: 14 May 2025

https://github.com/hardbyte/netchecks

Tool to validate assumptions about the network

cloud-native kubernetes-operator network-monitoring network-security security

Last synced: 16 May 2025

https://github.com/EdOverflow/proof-of-concepts

A little collection of fun and creative proof of concepts to demonstrate the potential impact of a security vulnerability.

bugbounty infosec poc proof-of-concept security

Last synced: 04 May 2025

https://github.com/Shnatsel/libdiffuzz

Custom memory allocator that helps discover reads from uninitialized memory

fuzz-testing fuzzing memory-allocator sanitizer security security-audit security-testing security-tools

Last synced: 02 Apr 2025

https://github.com/timokoessler/2faguard

A modern and secure Windows app for managing your 2FA authentication codes.

2fa authenticator collaborate github mfa portable security totp windows

Last synced: 12 Jan 2026

https://github.com/Vulnogram/Vulnogram

Vulnogram is a tool for creating and editing CVE information in CVE JSON format

cve cve-json cvss cvssv3 cwe json nvd security security-automation security-tools security-vulnerability vulnerability

Last synced: 29 Apr 2025

https://github.com/codecat/catsight

Cross-platform process memory inspector

cross-platform reverse-engineering security x64 x86-64

Last synced: 02 Sep 2025