An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/cloudposse/terraform-aws-sso

Terraform module to configure AWS Single Sign-On (SSO)

security terraform terraform-modules

Last synced: 04 Apr 2025

https://github.com/cert-lv/exchange_webshell_detection

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065)

blueteam exchange-server infosec iocs security security-audit

Last synced: 12 Jul 2025

https://github.com/diekmann/iptables_semantics

Verified iptables Firewall Ruleset Analysis

access-control firewall haskell iptables ipv4 ipv6 isabelle security

Last synced: 05 Sep 2025

https://github.com/secdec/attack-surface-detector-burp

The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters

dast pentesting security vulnerability

Last synced: 19 Apr 2025

https://github.com/itbackyard/CryptoNet

CryptoNet is simple, fast and a lightweight asymmetric and symmetric encryption library.

aes asymmetric-encryption cryptography csharp decryption encryption rsa rsa-cryptography security symmetric-encryption x509

Last synced: 14 Mar 2025

https://github.com/valpackett/secstr

Secure string library for Rust | now on https://codeberg.org/valpackett/secstr

rust security

Last synced: 30 Apr 2025

https://github.com/snawoot/steady-tun

Secure TLS tunnel with pool of prepared upstream connections

network-wrapper pool-server pooling pooling-utility security ssl ssl-pool tcp-proxy tls tls-proxy tls-tunnel

Last synced: 21 Jun 2025

https://github.com/Snowflake-Labs/sansshell

A non-interactive daemon for host management

administration automation go reliability security unshelled

Last synced: 12 May 2025

https://github.com/vitalk/ansible-secure-ssh

The ansible playbook to improve the security of your SSH

ansible security sensible-defaults ssh

Last synced: 16 Mar 2025

https://github.com/odino/wasec

Examples of security features (or mishaps) on web applications -- these are mostly examples and tutorials from the WASEC book.

book clickjacking csp security wasec websecurity xss

Last synced: 16 Mar 2025

https://github.com/igorhrcek/wp-cli-secure-command

Secure package for WP CLI, built to provide an easier way of securing your WordPress installation

apache hardening nginx security wordpress wp-cli wp-cli-package

Last synced: 01 Feb 2026

https://github.com/Kitura/BlueSSLService

SSL/TLS Add-in for BlueSocket using Secure Transport and OpenSSL

linux macos networking security socket swift

Last synced: 25 Mar 2025

https://github.com/htrgouvea/spellbook

Framework for rapid development of offensive security tools

bugbounty ctf exploit framework offensive-security pentest perl security security-tools

Last synced: 03 Sep 2025

https://github.com/c2fmzq/tlsproxy

TLSPROXY is a TLS termination proxy that provides automatic TLS encryption for various network services. It supports SSO, client authentication, and can act as a web server or reverse proxy.

ech golang http3 lets-encrypt mtls oidc passkey passkeys pki quic reverse-proxy security self-hosted sso tls-proxy tlspassthrough tpm

Last synced: 11 Feb 2026

https://github.com/spr-networks/super

📡 SPR: Open Source, secure, user friendly and fast wifi routers for your home. One wifi password per device. Ad Blocking & Privacy Blocklists. Policy Based Network Access

adblock alerting coredns golang homelab nftables router security security-tools self-hosted vpn wifi wifi-security wireguard

Last synced: 25 Dec 2025

https://github.com/cycodehq/cycode-cli

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning

code cycode sast sca secrets secure security

Last synced: 04 Feb 2026

https://github.com/thehlopster/hfuzz

Wordlist for web fuzzing, made from a variety of reliable sources including: result from my pentests, git.rip, ChatGPT, Lex, nuclei templates, web-scanners, seclist, bo0m, and more.

bugbounty fuzz fuzzing hacking pentesting security web-fuzzing wordlist

Last synced: 21 Apr 2025

https://github.com/zeroknots/slotmachine

detect hazardous storage writes in Solidity contracts

evm security solidity yul

Last synced: 15 Jun 2025

https://github.com/lirantal/essential-nodejs-security-book

Documentation for Essential Node.js Security

appsec nodejs owasp security

Last synced: 10 Jul 2025

https://github.com/rdohms/DMS-Filter

Library that offers Input Filtering based on Annotations for use with Objects. Check out 2.dev for 2.0 pre-release.

annotations filtering hacktoberfest security

Last synced: 16 Nov 2025

https://github.com/remvze/pswd

🔑 Simple secure password generator.

password password-generator privacy privacy-tools security security-tools

Last synced: 11 May 2025

https://github.com/opencomputeproject/security

Security Project

security

Last synced: 05 Oct 2025

https://github.com/jcsec-security/CosmWasm-audit-roadmap

Roadmap to get up to speed with CosmWasm smart contract audits and security vulnerabilities

audit blockchain bug bugbounty contract cosmos cosmossdk cosmwasm dapp defi hacking roadmap rust security smart smartcontract vulnerabilities

Last synced: 27 Aug 2025

https://github.com/lk-geimfari/secrets.clj

A library designed to generate cryptographically strong random numbers suitable for managing data such as passwords, account authentication, security tokens, and related secrets.

authentication choices clj clojure cryptography drng jvm password prng random rng secrets secure security timestamp tokens uuid xkcd

Last synced: 06 May 2025

https://github.com/rdohms/dms-filter

Library that offers Input Filtering based on Annotations for use with Objects. Check out 2.dev for 2.0 pre-release.

annotations filtering hacktoberfest security

Last synced: 09 Apr 2025

https://github.com/GoogleCloudPlatform/gke-security-scenarios-demo

This project demonstrates a series of best practices for improving the security of containerized applications deployed to Kubernetes Engine. You will deploy multiple instances of the same container image with a variety of security settings to illustrate the use of RBAC, security contexts, and AppArmor policies.

containers gke gke-helmsman google-cloud-platform kubernetes kubernetes-engine security

Last synced: 30 Apr 2025

https://github.com/bkbilly/AlarmPI

🚨 Home Security Intrusion Detection for Raspberry PI or any other linux OS

alarm android-application diy hikvision home-assistant ifttt-maker mqtt python raspberry-pi restful-api security voip zigbee

Last synced: 27 Jul 2025

https://github.com/web3batman/multi-chain-casino

Completed Casino(Crashr, Coinflip, Mines, BlackJack, etc) supported multi-chain(eth, sol, base, bitcoin, inj)

bitcoin casino-games encryption ethereum injective-protocol security solana

Last synced: 18 Oct 2025

https://github.com/justinmayer/kagi

WebAuthn security keys and TOTP multi-factor authentication for Django

2fa authentication django multi-factor-authentication security totp u2f webauthn

Last synced: 09 Apr 2025

https://github.com/aleluff/uktools

Upgrade latest Linux kernel automatically for Ubuntu and derivatives 🐧

bodhi-linux drivers elementary-os kernel linux linux-ck linux-kernel linux-mint purge security ubuntu update zorin-os

Last synced: 03 Apr 2025

https://github.com/Turing-Space/Honeypots-on-Blockchain

This repo collects almost all the smart contract honeypots that you could find in the first three pages of Google search.

blockchain ethereum hack honeypots security smart-contracts

Last synced: 12 May 2025

https://github.com/lucas-c/pre-commit-hooks-safety

A pre-commit hook to check your Python dependencies against safety-db

git-hooks pre-commit python safety-db security

Last synced: 05 Apr 2025

https://github.com/banxian/edureviver

J-Link v10/v11/v12 USB exploit utility

embedded-systems security usb

Last synced: 06 Apr 2025

https://github.com/nicohood/gpgit

A shell script that automates the process of signing Git sources via GPG

git gpg security signature

Last synced: 09 Oct 2025

https://github.com/wkrzywiec/keycloak-security-example

Sandbox project to play around with keyclaok and integrating it with Spring Boot and Angular apps (using OAuth 2.0 protocol)

angular java jwt keycloak learning learning-by-doing oauth2 security spring-boot

Last synced: 26 Mar 2025

https://github.com/googlecloudplatform/gke-security-scenarios-demo

This project demonstrates a series of best practices for improving the security of containerized applications deployed to Kubernetes Engine. You will deploy multiple instances of the same container image with a variety of security settings to illustrate the use of RBAC, security contexts, and AppArmor policies.

containers gke gke-helmsman google-cloud-platform kubernetes kubernetes-engine security

Last synced: 25 Oct 2025

https://github.com/k8gege/porttran

PortTran (.NET端口转发工具,支持任意权限)

hacking lcx pentest-tool portforward porttran security tunnel

Last synced: 23 Aug 2025

https://github.com/GrapheneOS/platform_bionic

Hardened Android standard C library. Some of the past hardening has not yet been ported from Marshmallow, Nougat and Oreo to this Android Pie repository. Most is available via archived tags in https://github.com/AndroidHardeningArchive/platform_bionic (check both the most recent Oreo and Nougat tags).

android grapheneos libc security

Last synced: 08 May 2025

https://github.com/tegal1337/shelly

Simple Backdoor Manager with Python (based on weevely)

python python-backdoor python3 security shell shelly

Last synced: 06 Apr 2025

https://github.com/BugBountyResources/targets

A collection of over 5.1 million sub-domains and assets belonging to public bug bounty programs, compiled into a repo, for performing bulk operations.

bugbounty cybersecurity information infosec recon reconnaissance security security-tools

Last synced: 11 Jul 2025

https://github.com/dionysio/haveibeenpwned_lastpass

Check if your lastpass passwords have been pwned by someone

haveibeenpwned lastpass password-manager python security

Last synced: 09 Jul 2025

https://github.com/Netflix-Skunkworks/historical

A serverless, event-driven AWS configuration collection service with configuration versioning.

aws cloudtrail dynamodb events lambda python s3 security securitygroups serverless

Last synced: 16 May 2025

https://github.com/interlynk-io/sbomasm

sbomasm: The Complete SBOM Management Toolkit

cyclonedx devsecops go golang gomodule oss sbom sbom-generator sbom-tool security spdx

Last synced: 12 Jan 2026

https://github.com/cr0hn/dockerfile-security

Static security checker for Dockerfiles

devops devsecops docker security static-analyzer

Last synced: 20 Aug 2025

https://github.com/leobeosab/sharingan

Offensive Security recon tool

dns go nmap recon security

Last synced: 16 Jan 2026

https://github.com/leesoh/yams

A collection of Ansible roles for automating infosec builds.

ansible penetration-testing security security-automation

Last synced: 09 May 2025

https://github.com/samogod/bugradar

Advanced external automation on bug bounty programs by running the best set of tools to perform scanning and finding out vulnerabilities.

automation bounty bug bug-bounty bugbounty bugbounty-tool bugcrowd hackerone osint recon recontool security security-automation security-tools

Last synced: 11 Jul 2025

https://github.com/rewindio/aws-security-hub-CIS-metrics

Metrics and alarms for AWS security hub for the CIS standard

alarm aws cis-benchmark cloudformation cloudformation-templates security

Last synced: 16 May 2025

https://github.com/0x48piraj/incarcero

Incarcero is a tool that creates Virtual Machines (VMs) preconfigured with malware analysis tools and security settings tailored for malware analysis without any user interaction.

malware malware-analysis malware-detection malware-research malware-samples research security

Last synced: 25 Aug 2025

https://github.com/rootup/smuggleshield

Protection against HTML smuggling attempts.

blueteam htmlsmuggling purpleteam redteam security

Last synced: 07 Apr 2025

https://github.com/nowsecure/dirtycow

radare2 IO plugin for Linux and Android. Modifies files owned by other users via dirtycow Copy-On-Write cache vulnerability

android cve dirtycow exploit security

Last synced: 09 Apr 2025

https://gitlab.com/expliot_framework/expliot

EXPLIoT - Internet of Things Security Testing and Exploitation framework

Exploitatio Internet of Things hacking iot security testing

Last synced: 01 Apr 2025

https://github.com/falcosecurity/event-generator

Generate a variety of suspect actions that are detected by Falco rulesets

go kubernetes-auditing security security-testing syscall

Last synced: 05 Apr 2025

https://github.com/initstring/lyricpass

Password wordlist generator using song lyrics for targeted bruteforce audits / attacks. Useful for penetration testing or security research.

infosec kali-linux password-generator penetration-testing security

Last synced: 25 Mar 2025

https://github.com/doyensec/ajpfuzzer

A command-line fuzzer for the Apache JServ Protocol (ajp13)

ajp ajp13 fuzzer security

Last synced: 02 Jul 2025

https://github.com/edoverflow/hacks

Some random scripts. Just trying to be like the cool kids.

security

Last synced: 23 Apr 2025

https://github.com/jordanpotti/offensiveclouddistribution

Leverage the ability of Terraform and AWS or GCP to distribute large security scans across numerous cloud instances.

bugbounty recon redteam scanning security

Last synced: 05 Oct 2025

https://github.com/skx/linux-security-modules

A place to store my toy linux-security modules.

kernel linux linux-security-module lsm security

Last synced: 23 Apr 2025

https://github.com/shivasurya/code-pathfinder

An open-source security suite aiming to combine structural code analysis with AI-powered vulnerability detection. Built for advanced structural search, derive insights, find vulnerabilities in code.

ai-agents ai-sast application-security code-scanning sast security security-tools static-analysis static-code-analysis structural-search

Last synced: 08 Feb 2026

https://github.com/mitre/inspec_tools

A command-line and ruby API of utilities, converters and tools for creating, converting and processing security baseline formats, results and data

checklist cis compliance converter disa disa-checklist inspec json mitre-corporation mitre-inspec security stig xccdf

Last synced: 20 Aug 2025

https://github.com/oleiade/motus

A dead simple password generator

cli password-generator rust security

Last synced: 12 May 2025

https://github.com/EdOverflow/hacks

Some random scripts. Just trying to be like the cool kids.

security

Last synced: 06 Apr 2025

https://github.com/hexa-org/policy-orchestrator

Hexa Policy Orchestrator enables you to manage all of your access policies consistently across software providers.

cloud-native policy-as-code security

Last synced: 30 Apr 2025

https://github.com/WinMin/Protocol-Vul

Some Vulnerability in the some protocol are collected.

protocol security vulnerabilities

Last synced: 11 Jul 2025

https://github.com/Foxboron/age-plugin-tpm

:key: TPM 2.0 plugin for age

age go-tpm golang security tpm tpm2

Last synced: 07 May 2025

https://github.com/poshsecurity/posh-syslog

Send SYSLOG messages from PowerShell

powershell powershell-gallery security syslog syslog-messages

Last synced: 10 Aug 2025

https://github.com/poshsecurity/Posh-SYSLOG

Send SYSLOG messages from PowerShell

powershell powershell-gallery security syslog syslog-messages

Last synced: 10 Apr 2025

https://github.com/netflix-skunkworks/swag-client

Cloud multi-account metadata management tool.

security

Last synced: 07 May 2025

https://github.com/veler/PaZword

A password manager made in UWP technology

csharp dropbox onedrive password-generator password-manager security uwp

Last synced: 28 Mar 2025

https://github.com/syss-research/nrf24-playset

Software tools for Nordic Semiconductor nRF24-based devices like wireless keyboards, mice, and presenters

nrf24 proof-of-concept security security-tools

Last synced: 10 Apr 2025

https://github.com/veler/pazword

A password manager made in UWP technology

csharp dropbox onedrive password-generator password-manager security uwp

Last synced: 25 Mar 2025

https://github.com/thegodenage/waffle

Web Application Firewall, made in go.

ddos ddos-protection golang hacktoberfest open-source security waf

Last synced: 22 Jan 2026

https://github.com/divineomega/laravel-password-exposed-validation-rule

🔒 Laravel validation rule that checks if a password has been exposed in a data breach.

data-breach laravel laravel-5-package laravel-validation passwords php security

Last synced: 19 Oct 2025

https://github.com/michaelehab/aes-verilog

Advanced encryption standard (AES128, AES192, AES256) Encryption and Decryption Implementation in Verilog HDL

aes aes-128 aes-192 aes-256 aes-decryption aes-encryption cryptography encryption encryption-decryption fpga fpga-board fpga-soc learn rtl security verilog verilog-hdl verilog-project

Last synced: 08 Feb 2026

https://github.com/edoverflow/bug-bounty-responses

A collection of response templates for invalid bug bounty reports.

bugbounty infosec security template

Last synced: 24 Feb 2025

https://github.com/Plazmaz/MongoDB-HoneyProxy

A honeypot proxy for mongodb. When run, this will proxy and log all traffic to a dummy mongodb server.

honeypot information-security infosec mongo mongodb proxy security

Last synced: 27 Mar 2025

https://github.com/jpcertcc/impfuzzy

Fuzzy Hash calculated from import API of PE files

clustering impfuzzy malware neo4j python security volatility

Last synced: 11 Sep 2025

https://github.com/Gigamick/burnernote

Burner Note is a free, ad-free and open source tool for securely sending text based notes that are encrypted and self destruct once read.

aes-256-cbc encrypt-then-mac privacy security self-destructing-messages

Last synced: 10 Sep 2025

https://github.com/openclarity/vmclarity

VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities

agentless cloud exploits leaked-secrets malware misconfigurations rootkits sbom secrets-detection security vulnerabilities vulnerability-scanners

Last synced: 06 Apr 2025

https://github.com/zomato/vinifera

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

github recon security

Last synced: 10 Jul 2025

https://github.com/nollium/cve-2024-9264

Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)

authenticated cve cve-2024-9264 exploit file-read-vulnerability grafana poc rce rce-exploit security vulnerability

Last synced: 06 Apr 2025

https://github.com/nextcloud/suspicious_login

Detect and warn about suspicious IPs logging into Nextcloud

deep-learning intrusion-detection machine-learning nextcloud-app privacy security

Last synced: 05 Apr 2025

https://github.com/traut/stixview

STIX2 graph visualisation library in JS

cti cyber-security cyber-threat-intelligence graph library security stix stix2

Last synced: 26 Oct 2025

https://github.com/capeprivacy/nitrogen

Nitrogen is a tool for deploying web services to AWS Nitro Enclaves.

aws confidential-computing docker nitro-enclaves security

Last synced: 04 Jul 2025