An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/bloomkd46/xhome

Unofficial Xfinity Home node.js library (SDK) to control your home security

home security xfinity

Last synced: 16 Feb 2026

https://github.com/dimon222/py-vmsshgen

Automatic generation of SSH keys for VM

automation hacktoberfest python security ssh

Last synced: 12 Jun 2025

https://github.com/spurreiter/proof-of-login

a proof-of-work for login or registration endpoints

login proof-of-work security

Last synced: 12 Jun 2025

https://github.com/janniclas/protection-poker

Protection Poker is an agile security game, similar to Planning Poker. It is used to explicitly integrate security features in the planning process.

agile information-security protection-poker security

Last synced: 31 Mar 2025

https://github.com/nisanth2004/springboot-3-jwt-authentication-authorization-part1

In the context of user authentication, JWTs are commonly used to authenticate users and provide them access to protected resources.

amingoscode api intellij-idea java jpa jparepository json jwt mysql oops rest role security securityfilterchain spring springboot3 token token-based-authentication

Last synced: 16 Apr 2026

https://github.com/turbot/flowpipe-mod-clickup

ClickUp pipeline library for the Flowpipe cloud scripting engine. Automation and workflows to connect ClickUp to the people, systems and data that matters.

automation clickup clickup-api cloud devops flowpipe flowpipe-mod hacktoberfest integrations low-code orchestration pipelines security workflow workflow-automation workflow-engine

Last synced: 19 Mar 2026

https://github.com/lupaxa-security-toolbox/certtool

A clean, modern, fully-typed Python CLI and library for generating self-signed X.509 certificates, certificate signing requests (CSRs), and private keys.

certificates lupaxa lupaxa-security-toolbox security the-lupaxa-project

Last synced: 02 Mar 2026

https://github.com/cityssm/express-abuse-points

Express.js middleware for tracking and blocking abusive behaviour.

abuse block express express-middleware expressjs middleware nodejs security

Last synced: 04 Feb 2026

https://github.com/deepraj1729/devsecops

All in One repo about my journey in DevSecOps

api-security cloud-security devops gcp security web-security

Last synced: 19 Mar 2026

https://github.com/guided-traffic/s3-encryption-proxy

A Go-based proxy that provides transparent encryption/decryption for S3 objects with envelope encryption.

encryption envelope-encryption proxy s3 security

Last synced: 09 May 2026

https://github.com/blackvoidx/google-dorker

Simple Google Dork Generator for Cybersecurity

bug-bounty bugbounty cybersecurity dork dorker google-dorks googledork osint security

Last synced: 04 Mar 2026

https://github.com/wolffcatskyy/awesome-crowdsec

A curated list of awesome CrowdSec resources, bouncers, integrations, and tools

awesome awesome-list crowdsec cybersecurity security

Last synced: 04 Mar 2026

https://github.com/bobberdolle1/maixcam-wildtrap

🎯 AI-Powered Camera Trap for MaixCAM | Hybrid Motion+YOLOv8 Detection | Telegram Notifications | Wildlife Monitoring & Security | 4 Detection Modes | Night Vision | Auto Storage Management | Production Ready

ai camera-trap computer-vision edge-ai embedded-systems iot maixcam maixpy motion-detection object-detection opencv python security telegram-bot wildlife yolov8

Last synced: 03 Jun 2026

https://github.com/containerssh/charts

The ContainerSSH Helm charts

devsecops docker kubernetes security ssh

Last synced: 20 Jul 2025

https://github.com/thanoskas/arrowhead_alarm

Home Assistant integration for Arrowhead alarm panels with advanced zone detection and multi-panel support

alarm alarm-panel arrowhead custom-integration eci esx hacs home-assistant home-automation security

Last synced: 16 Apr 2026

https://github.com/mediamonks/self-xss-console-banner

This module will log a self-xss banner to warn users about the self-xss security risk. This banner should be used for projects that have data behind a login.

security security-tools self-xss self-xss-warning

Last synced: 25 Mar 2025

https://github.com/lilithsec/lilith

Reads EVE files into SQL as well as search stored data.

eve ids lae perl pie sagan security suricata

Last synced: 01 Apr 2026

https://github.com/orislabsdev/gocore

Engineering-first HTTP backend library for Go focused on performance, security, and production-ready architecture.

backend go golang http jwt middleware performance production-ready rate-limiting rest-api security tls web-framework web-server

Last synced: 13 Apr 2026

https://github.com/naufalafif/agent-guard

Native macOS menu bar app that scans MCP servers and AI agent skills for security threats

ai-agents cisco macos mcp menu-bar security swift

Last synced: 02 Apr 2026

https://github.com/lex-lopez/e-commerce-app

This is real world, production ready app for e-commerce built with Spring Boot 3 + Maven, that implements proper auth with JWT, communication based on RESTful APIs and Database versioning using Flyway

cicd flyway github-actions jwt-authentication refresh-token restful-api security spring-security sprint-boot

Last synced: 17 Apr 2026

https://github.com/mbay7/claude-code-security

A 6-layer security framework for Claude Code workspaces: prompt injection detection, memory poisoning prevention, secrets scanning, behavioral audit logging, and pre-commit guardrails. Install in 5 minutes.

ai-security claude-code devtools mcp owasp prompt-injection security

Last synced: 02 Apr 2026

https://github.com/rashimrbrd/security

A comprehensive security management platform designed to protect users, applications, and infrastructure through advanced threat detection, access control, and real-time monitoring capabilities.

docker javascript-library maintenance security tools-and-automation tools-engineering wrangler

Last synced: 01 May 2026

https://github.com/aeliant/qfileencryptionbundle

Bundle to ease files encryption in Symfony

decryption encryption files gpg php security symfony

Last synced: 17 Apr 2026

https://github.com/goklab/guardvibe

Security MCP for vibe coding. 429 rules, 36 tools, CLI + doctor. Host security, auth coverage mapping, LLM-powered deep scan (IDOR/business logic), taint analysis, and CVE/supply-chain IOC detection for Next.js, Supabase, Clerk, Stripe, Prisma, Drizzle, Hono, GraphQL, AI SDK, MCP, and the AI-native stack.

ai-security claude clerk cursor cve drizzle hono mcp mcp-server nextjs owasp prisma prompt-injection sast security stripe supabase typescript vercel vibe-coding

Last synced: 07 Jun 2026

https://github.com/happycod3r/term-lock

Term-Lock is a simple pin system that allows you to block access and add a layer of security to your terminal.

bash bashrc extension oh-my-zsh-custom ohmyzsh omz omz-plugin security shell-extension shellscript term-lock terminal-security v1 zsh zshrc

Last synced: 17 Apr 2026

https://github.com/banhao/mdatp-iocs-delete

DEL-MDATP-IOC.ps1 is used to delete the IOCs on Microsoft Defender ATP.

azure mdatp microsoft powershell powershell-script security

Last synced: 17 Apr 2026

https://github.com/logicalhacking/secureuml-gui

A ArgoUML extensions for modelling SecureUML supporting various SecureUML dialects with and without support for Generic Break Glass concepts.

modelling-framework secure security uml

Last synced: 22 Jul 2026

https://github.com/jlpdeveloper/liquibase-security

Powershell module to keep secrets in keepass

keepass2 liquibase security

Last synced: 04 Apr 2026

https://github.com/edward62740/i2ds

Security sensor system with app control and cloud messaging capabilities.

efr32 fcm-notifications firebase freertos iot-sensors micrium security sub-ghz wifi

Last synced: 18 Apr 2026

https://github.com/askalf/truecopy

own your agent skills — vet, sign & pin every skill & MCP server before it runs. 68,560 skills scanned, 0 confirmed malicious; weekly watch over the official Claude Code plugin directory.

agent-security ai-agents claude-code mcp own-your-stack prompt-injection provenance security skills supply-chain

Last synced: 22 Jul 2026

https://github.com/askalf/strongroom

Own your agent secrets — your AI agent holds a scoped, single-use lease, never the raw API key. strongroom injects the real secret only at egress, so a leaked prompt or poisoned tool can't leak a credential. Encrypted vault · tamper-evident audit · zero deps · MCP server included. Part of Own Your Agent Security (redstamp · truecopy · strongroom).

agent-security ai-agents ai-security api-keys credentials least-privilege llm mcp own-your-stack secrets secrets-management security vault

Last synced: 22 Jul 2026

https://github.com/kubedoll-heavy-industries/agentcontainers

Immutable, reproducible, least-privilege runtime environments for AI agents

ai-agents containers devcontainers ebpf oci security slsa

Last synced: 18 Apr 2026

https://github.com/doctena-org/octorules-cloudflare

Cloudflare provider for octorules

cloudflare firewall iac octorules security waf yaml

Last synced: 18 Apr 2026

https://github.com/sjimenez44/azureroleassignmentauditor

Visualizes role assignments in an interactive network graph, helping security teams analyze access control structures.

azure dockerfile entraid security

Last synced: 18 Apr 2026

https://github.com/john-breton/water

A security focused Internet measurement framework to map the threat landscape for users that require accessibility tools to access the Internet

internet-measurements madweb23 python research-paper security selenium-python wcag21 web-accessibility

Last synced: 19 Apr 2026

https://github.com/pathak-ashutosh/pedigree-pal

Blockchain-based Dog Pedigree and Ownership Verification System

ethereum security solidity

Last synced: 07 May 2026

https://github.com/sap-samples/security-research-dp-hierarchical-text

SAP Security Research sample code to reproduce the research done in our paper “On the privacy-utility trade-off in differentially private hierarchical text classification".

research sample sample-code security

Last synced: 20 Apr 2026

https://github.com/branover/hexgraph

Self-hosted, agentic vulnerability research for binaries & firmware: an AI agent decompiles, fuzzes, and verifies exploits inside a sandbox, recording every finding to a typed graph. BYOK, fully local.

agentic-ai ai-agents binary-analysis claude claude-code cybersecurity exploit-development firmware-security fuzzing ghidra iot-security llm mcp pentesting reverse-engineering security security-tools vulnerability-research

Last synced: 04 Jun 2026

https://github.com/openai/fence

A fence keeps things out, but also in.

cicd github-actions security supply-chain-security

Last synced: 23 Jul 2026

https://github.com/roguh/ansible-fwknop

Ansible role that secures ports on your server from unauthorized access using fwknop, an improved port knocking utility.

ansible devops fwknop knocking networking port security yaml

Last synced: 20 Apr 2026

https://github.com/iam-py-test/unload-block-remover

Prevent websites from annoying you with 'Are you sure you want to leave'

annoyances browser-extension chrome-extension firefox-extension security unload

Last synced: 22 Apr 2026

https://github.com/magenx/tuzik

Go daemon for Linux that reads audit events from the audisp-af_unix Unix domain socket and automatically deletes or quarantines (moves) files that match a set of configurable rules as soon as they appear

auditd golang monitoring security

Last synced: 22 Apr 2026

https://github.com/konstantinullrich/openvas2defectdojo

OpenVAS2DefectDojo exports all new OpenVAS Reports from one or multiple OpenVAS instances to the local system.

defect-dojo openvas-reports python3 security

Last synced: 06 Jun 2026

https://github.com/prithvi1236/redactor

Redacts sensitive data from clipboard before you paste into ChatGPT, Claude, or any external AI — 100% local, no secrets leaves your machine.

desktop-app local-ai ner privacy python security

Last synced: 06 Jun 2026

https://github.com/dishine-digital-agency/cookie-audit

Most cookie consent setups are broken in ways nobody notices until an audit. This Puppeteer-powered CLI fires up a headless browser to capture, classify, and grade every cookie your site sets. Scan and get a categorized cookie inventory with GDPR compliance flags (470+ known cookies, automatic classification, multi-format reports).

automation compliance cookies developer-tools gdpr open-source privacy puppeteer python scanner security security-tools tracker-blocking web-scraping

Last synced: 25 Apr 2026

https://github.com/solomonneas/proxguard

Proxmox security auditor with config parsers, CIS benchmarks, and remediation scripts

firewall hardening homelab infrastructure proxmox security virtualization

Last synced: 25 Apr 2026

https://github.com/hi120ki/openaikeyserver

A server application that generates temporary OpenAI API keys for authorized users through Google OAuth2 authentication

ai aisecurity openai security

Last synced: 25 Apr 2026

https://github.com/daisvke/ft_otp

This program allows you to securely store an initial password in an encrypted file and generate a new TOTP (Time-based One-Time Password) every time it is requested. It provides both a CLI and a GUI version.

cpp cryptography ecole42 ft-otp otp-generator qrcode-generator qt security totp totp-generator

Last synced: 28 Feb 2025

https://github.com/tridentstack/wazuh-docker-secure

Secure Wazuh deployment automation for Docker with enhanced password management, certificate generation, and security hardening. Scripts for full setup and credential management that eliminate default passwords and implement security best practices.

docker mdr security siem soc tridentstack wazuh

Last synced: 26 Apr 2026

https://github.com/matouskozak/exe-scanner

A lightweight plugin that improves malware classifiers' robustness against adversarial attacks on Windows executables (EXEmples). Based on the research paper "Updating Windows Malware Detectors: Balancing Robustness and Regression against Adversarial EXEmples" (2025).

adversarial-machine-learning malware-detection security windows

Last synced: 27 Apr 2026

https://github.com/kstenschke/tiny-vault

Tiny Vault - Temporary local password store for Linux

linux password security tool

Last synced: 27 Apr 2026

https://github.com/sanjoy-sust/scpproject

This is Secure Communication Protocol for smart cart Cryptography management

aes aes-encryption algorithm cryptography design-patterns factory-method-pattern factory-pattern j2se java java-smart-cards security

Last synced: 07 Jun 2026

https://github.com/lucasgoncsilva/swarden

Created in Django as an MVC Framework, sWarden works as a real prototype of an online password and credential manager. This project uses security concepts in a practical and descriptive way.

criptography django load-testing password password-manager python security testing

Last synced: 28 Apr 2026

https://github.com/bylickilabs/hashchecker

HashChecker ist ein kompaktes, benutzerfreundliches Windows-Tool zur schnellen Integritätsprüfung von Dateien per Hashwert.

checksum csharp desktop-app dotnet file-integrity hash hash-checker integrity-checker md5 opensource security sha256 tools windows winforms

Last synced: 28 Apr 2026

https://github.com/xsscx/research

Security Research Tools for ICC Color Profiles

analysis color debugging icc icc-color-profile measurement profile research security

Last synced: 29 Apr 2026

https://github.com/davidyslu/bufferoverflowattack

Simulate a simple buffer overflow attack

assembly buffer-overflow-attack python security

Last synced: 29 Apr 2026

https://github.com/codewithashim/face-recognition-system

The Face Recognition System is a cutting-edge software application powered by state-of-the-art machine learning techniques. Experience accurate identification and verification of human faces in images and real-time video streams.

access-control biometrics codewithahsim deep-neural-networks face-recognition facial-detection facial-identification opencv opencv-python python python-3 real-time-face-recognition scalable-face-recognition security security-tools surveillance

Last synced: 29 Apr 2026

https://github.com/soumyadas15/lock

Lock is a drop-in security toolkit designed for modern applications. Whether you're building APIs, serverless functions, or microservices, Lock helps you secure your routes with a powerful, plug-and-play middleware.

api backend express microservice nextjs nodejs security typescript

Last synced: 30 Apr 2026

https://github.com/garretpatten/security-guardrails

Reusable GitHub Actions guardrails for pull requests: OpenGrep SAST, verified TruffleHog secrets, dependency review, and Trivy supply-chain checks — high signal, low noise.

ci-cd devsecops github-actions opengrep reusable-workflows sast sbom secret-scanning security supply-chain-security trivvy trufflehog

Last synced: 08 Jun 2026

https://github.com/m3ssap0/struts2_cve-2017-5638

This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.

cve-2017-5638 exploit security security-tools struts2 vulnerability vulnerability-scanners

Last synced: 10 Jun 2026

https://github.com/ctrly4sh/secure-rolebased-auth-api

Secure API with JWT authentication, AES encryption, and OAuth 2.0 with access control.

authentication backend for-resume nodejs security

Last synced: 08 Apr 2025

https://github.com/rivassec/secure-iam-lint

Python-based linter for AWS IAM policies to catch insecure configurations

automation aws devsecops iam linter python security

Last synced: 02 May 2026

https://github.com/inkedcat/kallbid

💰🔨 Cryptographically secure auction Client/Seller/Admin apps (Imported From School GitLab)

auction cryptography java javafx security

Last synced: 02 May 2026

https://github.com/emanuele-em/apple-security

Bindings to the macOS Security Framework

apple bindings framework ios keychain macos macosx rust security

Last synced: 02 May 2026

https://github.com/cryptix720/pimux

PIMUX: Manage and share your passwords, documents, private photos and other personal information with world-class security, right from your Windows desktop, Surface or phone.

document information password password-manager security windows windows-service

Last synced: 03 May 2026

https://github.com/potato-industries/souschef

stdin | CyberChef Recipes (encryption, decryption, encoding, decoding, etc) | stdout

cyberchef decoding decryption encoding encryption hashing nodejs recipes security shell stdin stdout

Last synced: 03 May 2026

https://github.com/arcjet/example-nextjs-bot-protection

An example Next.js site protected by Arcjet bot detection middleware.

arcjet bot-detection developer-tools javascript nextjs nodejs security security-tools typescript

Last synced: 04 May 2026

https://github.com/0xnu/thales

A CLI tool to automatically generate and update README.md files using ISO 639 language codes nomenclature by scanning project codebases.

cli code-quality code-review linux macos performance security utility windows

Last synced: 04 May 2026

https://github.com/brainstone/ansible_roles_user_management

Powerful Ansible role to manage user accounts on your systems including sshd config. Configures your sshd config, adds and removes users easily, sets their passwords, groups and authorized_keys.

ansible ansible-galaxy ansible-role security sshd sshd-config sudo

Last synced: 05 May 2026

https://github.com/anubissbe/github-runnerhub

Enterprise-grade GitHub Actions self-hosted runner management system with proxy architecture, auto-scaling, security scanning, and comprehensive monitoring

auto-scaling docker enterprise github-actions security self-hosted-runners typescript

Last synced: 05 May 2026

https://github.com/shazeus/ghspy

GitHub OSINT tool — extract intelligence from any GitHub user profile

cli developer-tools email-discovery github github-api intelligence osint python reconnaissance security terminal timezone

Last synced: 09 Jun 2026

https://github.com/cyanheads/nist-nvd-mcp-server

Search and audit CVEs by keyword, severity, CWE, CISA KEV status, and CPE via the NIST National Vulnerability Database. STDIO or Streamable HTTP.

bun cisa-kev cpe cve cvss mcp mcp-server model-context-protocol nist nvd security typescript vulnerability

Last synced: 29 May 2026

https://github.com/samjuk/ansible-ecomscan

Ansible role to manage running Ecomscan across multiple websites

ansible devsecops ecomscan magento2 malware sansec scanning security shopware woocommerce wordpress

Last synced: 07 May 2026

https://github.com/ngrsoftlab/astra-apache-httpd

Проект по сборке Apache HTTP Server на базе Astra Linux

apache2 astralinux best-practices devops docker httpd podman pre-commit security shell

Last synced: 07 May 2026

https://github.com/ai-infra-curriculum/ai-infra-security-learning

AI Infrastructure Security Engineer Learning Track - ML infrastructure security, model security, and compliance

advanced ai-infrastructure compliance curriculum gdpr hipaa learning machine-learning ml-security privacy security soc2

Last synced: 10 Jun 2026

https://github.com/mjc-gh/wcbin

🗄️ A static webpage for client-side encrypted archive files with the WebCrypto API

cryptography html5 javascript security webcrypto webcryptography-api

Last synced: 13 Sep 2025

https://github.com/containerssh/packages

The ContainerSSH packages page

devsecops docker kubernetes security ssh

Last synced: 09 May 2026

https://github.com/denizkarya1999/episecurity

Security app for Epitec to check every entry

asp-net-core blazor entry microsoft-sql-server security volunteering web-api

Last synced: 10 May 2026

https://github.com/jrhrmsll/openvpn-plus-squid

A proof of concept for an intermediary solution on the way to Zero Trust Networking; based on OpenVPN and Squid Proxy.

networking openvpn security squid zero-trust-network

Last synced: 10 May 2026