An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/forwardemail/reserved-email-addresses-list

List of 1250+ generic, admin, mailer-daemon, and no-reply usernames reserved for security concerns. Made for @forwardemail.

address addresses admin daemon email emails generic list local mailer no-reply parser reserved security user username

Last synced: 05 Apr 2025

https://gitlab.com/secure-system/Insular

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

android big brother privacy sandbox security surveillance

Last synced: 03 May 2025

https://github.com/cx330blake/black-hat-zig

This project provides some code examples of Zig for malwares, hacking, and red teaming. ⚡

hacking hacking-tool malware malware-research offensive-security red-teaming security zig

Last synced: 12 Oct 2025

https://github.com/codecat/catsight

Cross-platform process memory inspector

cross-platform reverse-engineering security x64 x86-64

Last synced: 02 Sep 2025

https://github.com/quarkslab/pyrrha

A tool for firmware cartography

firmware-analysis firmware-tools security

Last synced: 03 Feb 2026

https://github.com/SecAegis/SecAutoBan

恶意IP全自动封禁平台。支持收集如下安全设备告警:长亭WAF社区版(SafeLine)、微步蜜罐HFish、奇安信天眼、奇安信椒图、绿盟WAF、科来网络安全分析审计系统。支持如下设备联动封禁:RouterOS、OPNsense、CheckPoint、奇安信防火墙、旁路阻断(无需设备配合)

docker firewall hids sec security security-tools waf web-security

Last synced: 07 Sep 2025

https://github.com/siriusphp/validation

Framework agnostic validation library for PHP

forms input php sanitization security validation

Last synced: 13 Apr 2025

https://github.com/4ARMED/kubeletmein

Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.

kubelet kubernetes security

Last synced: 30 Apr 2025

https://github.com/byterocket/c4-common-issues

A collection of common security issues and possible gas optimizations in solidity smart contracts

audit c4 code4rena ethereum evm security solidity

Last synced: 26 Jul 2025

https://github.com/rond-authz/rond

A lightweight container for distributed security policy evaluation

authorization hacktoberfest openpolicyagent rbac security

Last synced: 11 May 2025

https://github.com/vdeville/ssh-login-alert-telegram

Recieive telegram notfications when user connect to a server

alert audit connections debian linux login security ssh telegram ubuntu

Last synced: 08 Apr 2025

https://github.com/yevh/vulnplanet

Vulnerable code snippets with fixes for Web2, Web3, API, iOS, Android and Infrastructure-as-Code (IaC)

android api application-security appsec-tutorials appsecurity bugbounty code codesecurity cve ios owasp owasp-top-10 pentesting poc security vulnerabilities vulnerability waf web2 web3

Last synced: 02 Jul 2025

https://github.com/0xmachos/apple-platform-security-guides

Every Apple Platform Security Guide

ios macos security tvos watchos

Last synced: 09 Apr 2025

https://github.com/typedb-osi/typedb-cti

Open Source Threat Intelligence Platform

cti cyber cybersecurity intelligence osint security threat-intelligence

Last synced: 16 Jan 2026

https://github.com/pdevito3/heimguard

🛡 A simple library that allows you to easily manage permissions in your .NET projects.

authorization dotnet permission permissions policy role roles security

Last synced: 16 May 2025

https://github.com/fiware/catalogue

Curated framework of open source platform software components using 𝑭𝑰𝑾𝑨𝑹𝑬 which can be assembled together to accelerate the development of Smart Solutions.

contextual-data data-publication fiware generic-enablers iot-agent monetization processing robotics security smart-app

Last synced: 11 Mar 2025

https://github.com/shabarkin/aws-enumerator

The AWS Enumerator was created for service enumeration and info dumping for investigations of penetration testers during Black-Box testing. The tool is intended to speed up the process of Cloud review in case the security researcher compromised AWS Account Credentials.

aws cloud hacking security security-audit security-tools

Last synced: 17 Jan 2026

https://github.com/scop/portecle

User friendly GUI application for creating, managing and examining keystores, keys, certificates, certificate requests, certificate revocation lists and more

certificate-files cryptography help-wanted java keypair keystore security

Last synced: 19 Jun 2025

https://github.com/spotify/gcp-audit

A tool for auditing security properties of GCP projects.

google-cloud google-cloud-platform security security-audit

Last synced: 12 May 2025

https://github.com/ramborogers/netventory

Netventory is a fast single binary network scanning tool with a beautiful TUI and WebUI that runs on Linux, Mac or Windows.

golang network security

Last synced: 05 Apr 2025

https://github.com/ddddddo/packemon

Packet monster (っ‘-’)╮=͟͟͞͞◒ ヽ( '-'ヽ) TUI tool for sending packets of arbitrary input and monitoring packets on any network interfaces (default: eth0).

ebpf linux network network-programming networking observability packet packet-analyzer packet-generator packet-monitoring pcap penetration-testing pentesting protocol routing-protocols security socket-programming sockets system-programming

Last synced: 05 Apr 2025

https://github.com/knownsec/Ethereum-Smart-Contracts-Security-CheckList

Ethereum Smart Contracts Security CheckList From Knownsec 404 Team

checklist ethereum ethereum-contract security smart-contracts

Last synced: 11 Jul 2025

https://github.com/i-core/werther

An Identity Provider for ORY Hydra over LDAP

active-directory authentication hydra identity ldap oauth2 openid-connect security

Last synced: 14 Jan 2026

https://github.com/addepar/redflag

RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and add reviewers. RedFlag's flexible configuration makes it valuable for any team.

ai ci-cd code-review security security-audit security-automation security-tools

Last synced: 27 Jan 2026

https://github.com/alertot/detectem

detectem - detect software and its version on websites.

detection detector python security

Last synced: 14 Dec 2025

https://github.com/G3G4X5X6/ultimate-cube

ultimate-cube 是开源的远程服务器管理工具,支持SSH,RDP,Telnet,COM等协议。

console java remote-access security sftp ssh telnet terminal toolbox

Last synced: 13 Apr 2025

https://github.com/tls-inspector/tls-inspector

Easily view and inspect X.509 certificates on your iOS device.

gplv3 https ios-app security ssl ssl-certificates tls tls-inspector x509

Last synced: 17 Mar 2025

https://github.com/detroitenglish/pw-pwnage-cfworker

Deploy a Cloudflare Worker to sanely score users' new passwords with zxcvbn AND check for matches against haveibeenpwned's 10+ billion breached accounts

cloudflare cloudflare-workers haveibeenpwned passwords security serverless zxcvbn

Last synced: 10 Oct 2025

https://github.com/SpectralOps/preflight

preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.

devops devsecops golang security

Last synced: 06 Feb 2026

https://github.com/optimajet/DWKit

DWKit is a Business Process Management System based on .NET Core and React

bpm csharp form-builder javascript jsx mssql net netcore2 postgresql react security webpack workflow workflow-designer

Last synced: 22 Jul 2025

https://github.com/wtfacademy/wtf-ctf

Collect CTFs related to evm, and provide solutions, using Foundry. 收集 EVM 类的 CTF 挑战,并提供解决方案。

blockchain ctf ethereum evm security solidity web3

Last synced: 10 Aug 2025

https://github.com/keep-starknet-strange/unruggable.meme

☣️ A framework for building safer memecoins 💸

memecoin security smart-contracts starknet token

Last synced: 30 Oct 2025

https://github.com/lensesio/lenses-docker

❤for real-time DataOps - where the application and data fabric blends - Lenses

dataops docker enterprise governance kafka kubernetes openshift security

Last synced: 11 Jun 2025

https://github.com/someengineering/cloud-security-list

A list of cloud security tools and vendors.

attack-surface-management aws azure cnapp cspm dspm gcp security siem

Last synced: 10 Apr 2025

https://github.com/brosck/reaper

「💀」Proof of concept on BYOVD attack

byovd development hacking malware offensivesecurity redteam security windows

Last synced: 04 Apr 2025

https://github.com/finos/git-proxy

Deploy custom push protections and policies on top of Git

gitops scans security

Last synced: 19 Jul 2025

https://github.com/Jpinsoft/DeepSound

Official DeepSound repository migrated from jpinsoft.net. DeepSound is a freeware steganography tool and audio converter that hides secret data into audio files. The application also enables you to extract secret files directly from audio files or audio CD tracks.

aes-256 audio c-sharp converter cryptography desktop-app encryption net-framework security steganography watermark wpf

Last synced: 02 Apr 2025

https://github.com/antgroup/cloudrec

CloudRec is an open source multi-cloud security posture management (CSPM) platform designed to help organizations improve the security of their cloud environments.

alibabacloud aws-security cloud cloud-security cspm cybersecurity devsecops gcp-security multi-cloud opa scans security

Last synced: 02 Aug 2025

https://github.com/redpwn/jail

An nsjail Docker image for CTF pwnables. Easily create secure, isolated xinetd/inetd-style services.

ctf docker inetd nsjail sandbox security xinetd

Last synced: 21 Jan 2026

https://github.com/jgrodziski/keycloak-clojure

A Clojure library helping the integration of Keycloak with a Clojure Application + a sample SPA Client and API Server demonstrating the Keycloak integration

authentication authorization clojure iam keycloak keycloak-clojure oauth2 oauth2-provider oidc oidc-provider re-frame realm security yada

Last synced: 02 Sep 2025

https://github.com/miguelripoll23/homebridge-securitysystem

Homebridge plugin that creates a security system accessory that can be triggered by HomeKit sensors

alarm homebridge homebridge-plugin homekit security

Last synced: 16 May 2025

https://github.com/rsmusllp/syringe

A General Purpose DLL & Code Injection Utility

c security

Last synced: 04 Jul 2025

https://github.com/WTFAcademy/WTF-CTF

Collect CTFs related to evm, and provide solutions, using Foundry. 收集 EVM 类的 CTF 挑战,并提供解决方案。

blockchain ctf ethereum evm security solidity web3

Last synced: 05 Apr 2025

https://github.com/MiguelRipoll23/homebridge-securitysystem

Homebridge plugin that creates a security system accessory that can be triggered by HomeKit sensors

alarm homebridge homebridge-plugin homekit security

Last synced: 06 Apr 2025

https://github.com/ddddddO/packemon

Packet monster (っ‘-’)╮=͟͟͞͞◒ ヽ( '-'ヽ) TUI tool for sending packets of arbitrary input and monitoring packets on any network interfaces (default: eth0).

ebpf linux network network-programming networking observability packet packet-analyzer packet-generator packet-monitoring pcap penetration-testing pentesting protocol routing-protocols security socket-programming sockets system-programming

Last synced: 28 Mar 2025

https://github.com/SSLMate/caa_helper

Generate a CAA policy

caa dns pki security

Last synced: 06 Apr 2025

https://github.com/yandex/burp-molly-scanner

Turn your Burp suite into headless active web application vulnerability scanner

automated-testing burp-extensions security vulnerability-scanners

Last synced: 12 Apr 2025

https://github.com/nebulock-inc/agentic-threat-hunting-framework

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

agentic-ai ai-agents automation cybersecurity detection-engineering pypi security security-tools siem threat-analysis threat-detection threat-hunting threat-intelligence threat-response thrunting

Last synced: 25 Jan 2026

https://github.com/php-casbin/think-casbin

专为ThinkPHP定制的Casbin的扩展包,Casbin是一个功能强大,高效的开源访问控制库。

abac access-control acl casbin permission rbac restful roles security thinkphp

Last synced: 25 Mar 2025

https://github.com/spectralops/preflight

preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.

devops devsecops golang security

Last synced: 15 Jul 2025

https://github.com/googlecloudplatform/gke-private-cluster-demo

This guide demonstrates creating a Kubernetes private cluster in Google Kubernetes Engine (GKE) running a sample Kubernetes workload that connects to a Cloud SQL instance using the cloud-sql-proxy "sidecar" authenticated using Workload Identity (Beta).

containers database gcp gke gke-helmsman gke-networking kubernetes kubernetes-engine postgres postgresql private-cluster security service-account workload-identity

Last synced: 03 Oct 2025

https://github.com/victoriadrake/ephemeral

Automatically delete your old Tweets with AWS Lambda

automation privacy privacy-tools security

Last synced: 03 Apr 2025

https://github.com/StellarSand/IYPS

A password strength app that evaluates and rates your password's robustness, estimates crack time, and provides helpful warnings and suggestions for stronger passwords.

android android-app android-application f-droid fdroid kotlin kotlin-android material-design material-ui material-you open-source password password-analysis password-cracker password-safety password-strength privacy security security-tools

Last synced: 21 Apr 2025

https://github.com/knownsec/ethereum-smart-contracts-security-checklist

Ethereum Smart Contracts Security CheckList From Knownsec 404 Team

checklist ethereum ethereum-contract security smart-contracts

Last synced: 19 Jun 2025

https://github.com/beatswitch/lock-laravel

This package is a Laravel 5 driver for Lock

acl laravel permissions php security

Last synced: 13 May 2025

https://github.com/symfonycorp/security-checker-action

The PHP Security Checker

cve php security

Last synced: 06 Apr 2025

https://github.com/openwall/yescrypt

Password-based key derivation function and password hashing scheme building upon scrypt

hash hashing kdf password pbkdf scrypt security

Last synced: 05 Apr 2025

https://github.com/GreyNoise-Intelligence/pygreynoise

Python3 library and command line for GreyNoise

internet scanning security threat-intelligence

Last synced: 10 May 2025

https://github.com/sofastack/sofa-hessian

An internal improved version of Hessian3/4 powered by Ant Group CO., Ltd.

hessian security sofa-rpc sofastack

Last synced: 15 Jan 2026

https://github.com/faizann24/rogue

Automated web vulnerability scanning with LLM agents

agents hacking llms pentesting security

Last synced: 29 Dec 2025

https://github.com/yorkie/rust.js

Run your JavaScript apps backed by Rust

javascript js performance rust security

Last synced: 20 Jun 2025

https://github.com/cgosec/Blauhaunt

A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts

analysis cyber-crime dfir forensics graph incident-response investigation security velociraptor

Last synced: 11 May 2025

https://github.com/falcosecurity/falco-talon

Response Engine for managing threats in your Kubernetes

falco kubernetes response-engine security

Last synced: 04 Apr 2025

https://github.com/yevh/VulnPlanet

Vulnerable code snippets with fixes for Web2, Web3, API, iOS, Android and Infrastructure-as-Code (IaC)

android api application-security appsec-tutorials appsecurity bugbounty code codesecurity cve ios owasp owasp-top-10 pentesting poc security vulnerabilities vulnerability waf web2 web3

Last synced: 04 Sep 2025

https://github.com/robur-coop/albatross

Albatross: orchestrate and manage MirageOS unikernels with Solo5

deployment mirageos ocaml orchestration provisioning security unikernel virtual-machine

Last synced: 16 May 2025

https://github.com/dev-sec/cis-dil-benchmark

CIS Distribution Independent Linux Benchmark - InSpec Profile

audit baseline devsec hardening inspec linux security

Last synced: 16 May 2025

https://github.com/optimajet/dwkit

DWKit is a Business Process Management System based on .NET Core and React

bpm csharp form-builder javascript jsx mssql net netcore2 postgresql react security webpack workflow workflow-designer

Last synced: 04 Apr 2025

https://github.com/7c/fakefilter

reliable fake and temp email filter solution for site operators

email security

Last synced: 05 Apr 2025

https://github.com/kpcyrd/i-probably-didnt-backdoor-this

A practical experiment on supply-chain security using reproducible builds

reproducible-builds security supply-chain

Last synced: 13 Apr 2025

https://github.com/RossGeerlings/webstor

WebStor efficiently enumerates all websites across your organization’s networks and those in your DNS records - including cloud-hosted servers via zone transfer data - stores their responses, and lets you query for known web technologies, including those with zero-day vulnerabilities.

attack-surface bugbounty bugbounty-tool cybersecurity footprinting information-gathering infosec pentest-scripts pentest-tools pentesting pentesting-tools recon reconnaissance security security-tools

Last synced: 12 Jul 2025

https://github.com/dependabot/elixir-security-advisories

Old database of Elixir security advisories before the GitHub Security Advisory DB supported Hex / Elixir.

elixir security

Last synced: 07 May 2025

https://github.com/osipxd/encrypted-datastore

Extensions to store DataStore in EncryptedFile

android datastore encrypted encryption security tink

Last synced: 04 Apr 2025

https://github.com/instructure/paseto

A paseto implementation in rust.

dogs-over-cats paseto security token

Last synced: 02 Apr 2025

https://github.com/cr0hn/enteletaor

Message Queue & Broker Injection tool

broker hacking hacking-tool python rabbitmq redis scanner security

Last synced: 09 Apr 2025

https://github.com/mitre/saf

The MITRE Security Automation Framework (SAF) Command Line Interface (CLI) brings together applications, techniques, libraries, and tools developed by MITRE and the security community to streamline security automation for systems and DevOps pipelines

compliance devsecops json mitre mitre-corporation mitre-saf security security-automation security-automation-framework

Last synced: 15 May 2025

https://github.com/mcp-shark/mcp-shark

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between your IDE and MCP servers

electron forensic-analysis forensics forensics-tools mcp-protocol monitoring monitoring-tool nodejs security security-audit security-tools traffic-analysis

Last synced: 25 Jan 2026

https://github.com/tijme/not-your-average-web-crawler

A web crawler (for bug hunting) that gathers more than you can imagine.

bug-bounty callbacks crawler custom get post python request scanner scraper security spider vulnerability

Last synced: 06 Apr 2025

https://github.com/rcbj/oauth2-oidc-debugger

An OAuth2 and OpenID Connect Debugger

authentication debugger oauth2 oidc openidconnect security

Last synced: 02 Apr 2025

https://github.com/jakejarvis/subtake

Automatic finder for subdomains vulnerable to takeover. Written in Go, based on @haccer's subjack.

bug-bounty go golang infosec pentesting security subdomain subdomain-takeovers takeover

Last synced: 04 Sep 2025

https://github.com/ggp1/kure

CLI password manager with sessions

command-line cryptography password-manager privacy security

Last synced: 15 Dec 2025