An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/ggp1/kure

CLI password manager with sessions

command-line cryptography password-manager privacy security

Last synced: 15 Dec 2025

https://github.com/PI-Defender/pi-defender

Kernel Security driver used to block past, current and future process injection techniques on Windows Operating System.

anti-injection anti-malware antivirus blue-team defense driver kernel malware process-injection security windows

Last synced: 20 Apr 2025

https://github.com/steccas/stecCA

An easy to deploy Certificate Authority / Public Key Infrastructure using CFSSL, Lemur and Docker magic!

certificate-authority certificates cfssl cloudflare deploy docker docker-compose easy lemur netflix oscp oscp-responder pki security server signing ssl ssl-certificates tls tls-certificate

Last synced: 26 Mar 2025

https://github.com/m0nad/dns-discovery

DNS-Discovery is a multithreaded subdomain bruteforcer.

bugbounty c dns multithreading network network-analysis security security-tools

Last synced: 12 Apr 2025

https://github.com/rhaidiz/dribble

Stealing Wi-Fi passwords via browser's cache poisoning.

bettercap bettercap-ng hacking poisoning raspberry raspberry-pi security wardriving wireless

Last synced: 12 Aug 2025

https://github.com/linux-lock/bpflock

bpflock - eBPF driven security for locking and auditing Linux machines

bpf containers ebpf iot iot-security kernel kubernetes lsm security

Last synced: 12 Apr 2025

https://github.com/samsar4/comptia-security-sy0-501-study-guide

Study Guide for CompTIA Security+ SY0 501 exam

certification-prep comptia security

Last synced: 28 Jan 2026

https://github.com/hahwul/deadfinder

🏴‍☠️ Find dead-links (broken links)

broken-links dead-links hacktoberfest security seo seo-optimization

Last synced: 16 May 2025

https://github.com/jwilk/traversal-archives

archive file samples for testing against directory traversal

security

Last synced: 11 Sep 2025

https://github.com/nickdeis/eslint-plugin-no-secrets

An eslint plugin to find strings that might be secrets/credentials

eslint eslint-plugin eslint-rules security security-tools

Last synced: 15 May 2025

https://github.com/karthikuj/sasori

Sasori is a dynamic web crawler powered by Puppeteer, designed for lightning-fast endpoint discovery.

automation crawler crawling dast dynamic endpoint-discovery infosec puppeteer scraping security

Last synced: 15 Aug 2025

https://github.com/burpheart/cdnlookup

一个使用 Edns-Client-Subnet(ECS) 遍历智能CDN节点IP地址的工具

dns infosec security security-tools

Last synced: 16 Jan 2026

https://github.com/symph0nia/cyberedge

互联网资产综合扫描/攻击面测绘

cybersecurity redteam scanner security

Last synced: 05 Apr 2025

https://github.com/Symph0nia/CyberEdge

互联网资产综合扫描/攻击面测绘

cybersecurity redteam scanner security

Last synced: 31 Oct 2025

https://github.com/chainreactors/malefic

IoM implant, C2 Framework and Infrastructure

c2 security

Last synced: 05 Apr 2025

https://github.com/0xTeles/jsleak

a Go code to detect leaks in JS files via regex patterns

bugbounty golang scanner security

Last synced: 11 Jul 2025

https://github.com/lissy93/email-comparison

📬 A quick comparison of private and / or secure email providers

email hacktoberfest parcel privacy security

Last synced: 07 May 2025

https://github.com/sp4rkw/Cyberspace_Security_Learning

在学习CTF、网络安全路上整合自己博客和一些资料,持续更新~

ctf learning security tips-ctf

Last synced: 11 Jul 2025

https://github.com/q1271964185/cyberspace_security_learning

在学习CTF、网络安全路上整合自己博客和一些资料,持续更新~

ctf learning security tips-ctf

Last synced: 31 Mar 2025

https://github.com/vulsio/gost

Build a local copy of Security Tracker. Notify via E-mail/Slack if there is an update.

freebsd go golang linux security vulnerability-databases

Last synced: 12 Apr 2025

https://github.com/j3ssie/goverview

goverview - Get an overview of the list of URLs

browser bugbounty chromedp favicon favicon-generator infosec recon screenshot security

Last synced: 23 Jul 2025

https://github.com/zeek/packages

The default package source of the Zeek Package Manager. Wrote a package? See the README for how to get it included.

bro network-monitoring nsm package-management packages pcap plugins security

Last synced: 31 Jan 2026

https://github.com/cassidoo/better-security-questions

Better security questions for easy use in your projects

questions security

Last synced: 13 Apr 2025

https://github.com/really-simple-plugins/really-simple-ssl

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate generation.

security ssl wordpress

Last synced: 04 Apr 2025

https://github.com/avilum/portsscan

A web client port-scanner written in GO, that supports the WASM/WASI interface for Browser WebAssembly runtime execution.

fingerprinting golang-webassembly knocker localhost port-knock port-knocker port-knocking portscanner security webassembly

Last synced: 16 Mar 2025

https://github.com/mhausenblas/k8s-sec

Kubernetes Security: from Image Hygiene to Network Policies

kubernetes security

Last synced: 12 Apr 2025

https://github.com/jwilk/url.sh

this URL is also malicious(?!) shell script

security

Last synced: 05 Apr 2025

https://github.com/mbalabash/sdc-check

Small tool to inform you about potential risks in project dependencies list

audit npm security supply-chain-security

Last synced: 10 Oct 2025

https://github.com/Sanix-Darker/Lazymux

Lazymux is a huge list of Many Hacking tools and PEN-TESTING tools! NOTE: Am not Responsible of bad use of this project.

hackathon hacker hacking hacking-code hacking-tools linux linux-app protection python security security-tools ssh termux termux-api termux-hacking termux-metasploit termux-tool

Last synced: 11 Mar 2025

https://github.com/j0lvera/next-csrf

CSRF mitigation for Next.js

csrf csrf-protection next nextjs node security

Last synced: 17 Aug 2025

https://github.com/salesforce/metabadger

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).

automation aws cloud-security hardening metadata security

Last synced: 07 Apr 2025

https://github.com/Samsar4/CompTIA-Security-SY0-501-Study-Guide

Study Guide for CompTIA Security+ SY0 501 exam

certification-prep comptia security

Last synced: 29 Apr 2025

https://github.com/a0xnirudh/kurukshetra

Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.

appsec infosec php secure-coding security

Last synced: 13 May 2025

https://github.com/yorcreative/laravel-scrubber

A Laravel package to scrub sensitive information that breaks operational security policies from being leaked on accident or not by developers.

cyber-security cybersecurity data-sanitization data-scrubber laravel laravel-package log log-sanitization log-scrubber logscrubber php scrubber security security-scan security-tools sensitive-data-security

Last synced: 02 Feb 2026

https://github.com/janreges/siteone-crawler

SiteOne Crawler is a website analyzer and exporter you'll ♥ as a Dev/DevOps, QA engineer, website owner or consultant. Works on all popular platforms - Windows, macOS and Linux (x64 and arm64 too).

analyzer crawler crawling performance qa quality-assessment security seo seotools stress-testing swoole testing website

Last synced: 14 Mar 2025

https://github.com/anirudhbiyani/findmytakeover

find dangling domains in a multi cloud environment

aws azure cloud dns gcp security security-tools subdomain subdomain-takeover

Last synced: 11 May 2025

https://github.com/hahwul/urx

Extracts URLs from OSINT Archives for Security Insights

osint osint-tool security url urx wayback-machine

Last synced: 02 Jul 2025

https://github.com/matank001/cursor-security-rules

This repository contains Cursor Security Rules designed to improve the security of both development workflows and AI agent usage within the Cursor environment. These rules aim to enforce safe coding practices, control sensitive operations, and reduce risk in AI-assisted development.

agent-security agents ai aiagents cursor cursor-rules cursor-security cursorrules security

Last synced: 17 Jan 2026

https://github.com/rollerworks/passwordstrengthbundle

Symfony Password strength and blacklisting validator bundle

bundle password password-strength php security symfony symfony-bundle

Last synced: 12 Apr 2025

https://github.com/dosx-dev/batchtoapp

Convert your .bat/.cmd scripts to .exe and protect (obfuscate) them with BatchToApp!

batch batch-app batch-script cmd compiler compilers converter desktop obfuscation obfuscator packer protection protector security terminal windows

Last synced: 07 May 2025

https://github.com/Rezilion/mi-x

Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploitability (runtime execution, configuration, permissions, existence of a mitigation, OS, etc..)

appsec security vulnerability-assessment vulnerability-validation

Last synced: 07 May 2025

https://github.com/fergarrui/ethereum-security

Security issues in Ethereum demonstrated in mocha tests. The fix is also demonstrated

ethereum mocha-tests security smart-contracts solidity solidity-security

Last synced: 22 Apr 2025

https://github.com/dev-sec/ansible-mysql-hardening

This Ansible role provides security configuration for MySQL.

ansible database hardening mysql mysql-hardening playbook protection role security

Last synced: 09 May 2025

https://github.com/danielstjules/blankshield

Prevent reverse tabnabbing phishing attacks caused by _blank

javascript noopener phishing-attacks security tabnabbing

Last synced: 09 Apr 2025

https://github.com/Cuprate/cuprate

Cuprate, an upcoming experimental, modern & secure Monero node. Written in Rust

cryptocurrency monero monero-integrations monerod network network-programming peer-to-peer rust rust-lang security

Last synced: 29 Sep 2025

https://github.com/fuko-php/masked

Mask sensitive data: replace blacklisted elements with redacted values

black-list blacklist fuko fuko-php mask masked obfuscation redact security

Last synced: 16 Jan 2026

https://github.com/dinosaure/bob

A peer-to-peer file-transfer tool in OCaml

file p2p security sharing unikernel

Last synced: 07 May 2025

https://github.com/leon3s/wireguard-gui

A wireguard client GUI for Linux made with nextauri

linux security vpn vpn-client wireguard

Last synced: 05 Apr 2025

https://github.com/gosecure/csp-auditor

Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website

burp burp-plugin csp hacktoberfest http security zap zap-plugin

Last synced: 05 Apr 2025

https://github.com/DigeeX/raider

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

authentication digeex hylang python raiderauth security

Last synced: 12 Jul 2025

https://github.com/ossf-cve-benchmark/ossf-cve-benchmark

The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebases using a variety of static analysis security testing (SAST) tools and generate reports to evaluate those tools.

benchmark cve open-source security vulnerability

Last synced: 07 May 2025

https://github.com/rafaeltoledo/android-security

An app showcase of some techniques to improve Android app security

android android-security app-security security

Last synced: 26 Mar 2025

https://github.com/p3nt4/invoke-tmpdavfs

Memory Backed Powershell WebDav Server

powershell security

Last synced: 29 Jul 2025

https://github.com/sanix-darker/lazymux

Lazymux is a huge list of Many Hacking tools and PEN-TESTING tools! NOTE: Am not Responsible of bad use of this project.

hackathon hacker hacking hacking-code hacking-tools linux linux-app protection python security security-tools ssh termux termux-api termux-hacking termux-metasploit termux-tool

Last synced: 03 Oct 2025

https://github.com/viralmaniar/peekaboo

PeekABoo tool can be used during internal penetration testing when a user needs to enable Remote Desktop on the targeted machine. It uses PowerShell remoting to perform this task. Note: Remote desktop is disabled by default on all Windows operating systems.

bluekeep infrastructure-testing internal-pentest network-pentest pentest pentest-tool pentest-tools pentesters pentesting powershell remote-desktop security security-tools

Last synced: 16 Jul 2025

https://github.com/GoSecure/csp-auditor

Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website

burp burp-plugin csp hacktoberfest http security zap zap-plugin

Last synced: 31 Mar 2025

https://github.com/tasooshi/pentesting-cookbook

A set of recipes useful in pentesting and red teaming scenarios

cheatsheet pentesting redteam security security-tools

Last synced: 11 Jul 2025

https://github.com/d00movenok/htmlsmuggler

✉️ HTML Smuggling generator&obfuscator for your Red Team operations

cybersecurity htmlsmuggling opsec pentest pentesting phishing redteam security smuggling

Last synced: 20 Jun 2025

https://github.com/JPCERTCC/DetectLM

Detecting Lateral Movement with Machine Learning

deep-learning elasticsearch kibana machine-learning powershell python security

Last synced: 30 Apr 2025

https://github.com/abdennour/certified-kubernetes-security-specialist

References for CKS Exam Objectives - Certified Kubernetes Security Specialist

certification cks ckss golang hardening kubernetes kubernetes-security security

Last synced: 16 Jun 2025

https://github.com/nielsfaber/alarmo-card

Home Assistant card for controlling the Alarmo component

alarm alarmo assistant card home home-assistant lovelace security

Last synced: 24 Oct 2025

https://github.com/cvebase/cvebase.com

cvebase is a community-driven vulnerability data platform to discover the world's top security researchers and their latest disclosed vulnerabilities & PoCs

cve cybersecurity infosec security vulnerabilities wiki

Last synced: 11 Jul 2025

https://github.com/santosomar/who_and_what_to_follow

Who and what to follow in the world of cyber security

cyber-security cybersecurity incident-response malware network news security

Last synced: 16 Jan 2026

https://github.com/in-toto/in-toto-golang

A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.

in-toto security software-supply-chain

Last synced: 23 Jan 2026

https://github.com/xfernando/go2seccomp

Generate seccomp profiles from go binaries

containers go seccomp security

Last synced: 12 Jan 2026

https://github.com/ReversecLabs/drozer-agent

The Android Agent for the Drozer Security Assessment Framework.

android drozer java mobile mobsec mwr pentesting security withsecure

Last synced: 11 Jul 2025

https://github.com/piccolo-orm/piccolo_api

ASGI middleware for authentication, rate limiting, and building REST endpoints.

asgi asyncio authentication fastapi hacktoberfest orm piccolo rate-limiting rest security starlette

Last synced: 04 Apr 2025

https://github.com/secrethub/secrethub-cli

A secrets management platform that every engineer can use with minimal code changes.

cli devops go golang secret-management secrets secrets-management security

Last synced: 06 May 2025

https://github.com/aapanel/aawaf

堡塔云WAF,宝塔免费(free)的私有云网站应用防火墙(firewall),基于docker/nginx/lua开发

acl captcha cc-attack ddos ddos-attacks ddos-defense ddos-protection docker firewall http-flood modsecurity nginx security security-tools sqli-injection waf web-application-firewall web-security xss

Last synced: 07 Apr 2025

https://github.com/Kostassoid/lethe

Secure drive wipe

disk drive erase secure security storage wipe

Last synced: 13 Mar 2025

https://github.com/nullarray/netset

Operational Security utility and automator.

automation bash infosec netsec opsec security tor

Last synced: 13 Apr 2025

https://github.com/kostassoid/lethe

Secure drive wipe

disk drive erase secure security storage wipe

Last synced: 16 May 2025

https://github.com/checkmarx/2ms

Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git

api-keys appsec secret-keys secret-management secrets security

Last synced: 21 Oct 2025

https://github.com/jpcertcc/malconfscan-with-cuckoo

Cuckoo Sandbox plugin for extracts configuration data of known malware

cuckoo-sandbox malware memory python security volatility

Last synced: 23 Jul 2025

https://github.com/tyki6/MyJWT

A cli for cracking, testing vulnerabilities on Json Web Token(JWT)

blackarch blackarch-packages cli ctf jsonwebtoken jwt pentest pentesting pypi python rawsec root-me rootme security security-tools websec

Last synced: 12 Jul 2025

https://github.com/sandflysecurity/sandfly-entropyscan

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with cryptographic hashes.

blueteam blueteamin incident-response incident-response-tooling intrusion-detection intrusion-detection-system linux malware malware-analysis malware-research security

Last synced: 21 Jan 2026

https://github.com/securityjoes/ForensicMiner

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

automation cortex crowdstrike cyber dfir edr fast forensics ir mdr powershell security soc xdr

Last synced: 11 May 2025

https://github.com/cado-security/rip_raw

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

dfir dfir-automation forensic-analysis forensics memory-forensics security

Last synced: 12 Jul 2025

https://github.com/peterdavehello/url-shorteners

A comprehensive, high-quality URL shorteners domain list for whitelist/allowlist or blacklist/blocklist purposes, utilized by NextDNS, ControlD, RethinkDNS, dnslow.me, and other OSINT projects.

adguard-blocklist allowlist blacklist blocking blocklist cyber-security dns dnsbl domain hacktoberfest hosts malware osint phishing pihole privacy security threat-intelligence url-shortener whitelist

Last synced: 04 Apr 2025