An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/ullaakut/gorsair

Gorsair gives root access on remote docker containers that expose their APIs

docker infosec netsec nmap penetration-testing pentesting security

Last synced: 02 Apr 2025

https://github.com/hluwa/Wallbreaker

๐Ÿ”จ Break Java Reverse Engineering form Memory World!

android debug debugger frida java python reverseengineering security

Last synced: 27 Mar 2025

https://github.com/SmartContractSecurity/SWC-registry

Smart Contract Weakness Classification and Test Cases

ethereum security smart-contracts

Last synced: 17 Apr 2025

https://github.com/sethvargo/ratchet

A tool for securing CI/CD workflows with version pinning.

cicd dependency security

Last synced: 16 May 2025

https://github.com/vincentcox/StaCoAn

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

bugbounty mobile-security security security-tools static-code-analysis

Last synced: 19 Mar 2025

https://github.com/Netflix/Fido

security

Last synced: 04 Apr 2025

https://github.com/sektioneins/pcc

PHP Secure Configuration Checker

configuration php security

Last synced: 27 Apr 2025

https://github.com/OWASP/DevSecOpsGuideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

devsecops owasp security shift-left

Last synced: 18 Jul 2025

https://github.com/brunty/awesome-checker-services

โœ… List of links to the various checkers out there on the web for sites, domains, security etc.

checker dns hacktoberfest list load-testing mail-configuration mobile-friendly security seo speed website website-performance

Last synced: 16 Jan 2026

https://github.com/simpleidserver/simpleidserver

OpenID, OAuth 2.0, SCIM2.0, UMA2.0, FAPI, CIBA & OPENBANKING Framework for ASP.NET Core

ciba dotnet-core fapi identity oauth2 openid openid-providers scim2 security uma2

Last synced: 15 May 2025

https://github.com/enkidevs/curriculum

๐Ÿ‘ฉโ€๐Ÿซ ๐Ÿ‘จโ€๐Ÿซ The open-source curriculum of Enki!

ai algorithms blockchain chatgpt computer-science css curriculum data-science education enki git gpt4 html java javascript learn-to-code linux python security sql

Last synced: 15 May 2025

https://github.com/chromium/hstspreload.org

:lock: Chromium's HSTS preload list submission website.

chrome chromium hsts hstspreload https security

Last synced: 13 Apr 2025

https://github.com/legit-labs/legitify

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

ci devops devsecops github gitlab golang sdlc-security security security-scanner supply-chain-security

Last synced: 15 May 2025

https://github.com/cisco-ai-defense/mcp-scanner

Scan MCP servers for potential threats & security findings.

agents ai mcp security

Last synced: 16 Feb 2026

https://github.com/prateek147/DVIA-v2

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security enthusiasts/professionals or students to test their iOS penetration testing skills in a legal environment. This project is developed and maintained by @prateekg147. The vulnerabilities and solutions covered in this app are tested up to iOS 11. The current version is writen in Swift and has the following vulnerabilities.

ios-swift jailbreak mobile-app security

Last synced: 12 Jul 2025

https://github.com/jvoisin/snuffleupagus

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

c elephant hardening php php-module php7 security security-hardening

Last synced: 07 Jan 2026

https://github.com/tankerhq/sdk-js

Tanker client-side encryption SDK for JavaScript

cryptography encryption end-to-end javascript privacy sdk security tanker

Last synced: 14 May 2025

https://github.com/Legit-Labs/legitify

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

ci devops devsecops github gitlab golang sdlc-security security security-scanner supply-chain-security

Last synced: 01 Apr 2025

https://github.com/TankerHQ/sdk-js

Tanker client-side encryption SDK for JavaScript

cryptography encryption end-to-end javascript privacy sdk security tanker

Last synced: 23 Mar 2025

https://github.com/netheril96/securefs

Filesystem in userspace (FUSE) with transparent authenticated encryption

authentication cloud crypto cryptography encryption filesystem filesystems fuse fuse-filesystem security

Last synced: 21 Oct 2025

https://github.com/0xbug/SQLiScanner

Automatic SQL injection with Charles and sqlmap api

autoscan scanner security security-audit security-vulnerability sqlmap sqlmap-webui sqlmapapi

Last synced: 02 Apr 2025

https://github.com/firefart/stunner

Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers.

exploit misconfiguration security stun testing tool turn webrtc

Last synced: 15 May 2025

https://github.com/jiaoxianjun/btle

Bluetooth Low Energy (BLE) packet sniffer and transmitter for both standard and non standard (raw bit) based on Software Defined Radio (SDR).

angle-of-arrival baseband bladerf ble bluetooth-low-energy dsp hackrf indoor-positioning packet-sniffer protocol-analyser protocol-parser rf sdr security sniffer software-defined-radio wireless-communication wireless-security wireless-sensor-networks

Last synced: 15 May 2025

https://github.com/snyk/zip-slip-vulnerability

Zip Slip Vulnerability (Arbitrary file write through archive extraction)

security vulnerabilities

Last synced: 27 Jan 2026

https://github.com/google/paranoid_crypto

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

cryptography security

Last synced: 18 Apr 2025

https://github.com/mspnp/cloud-design-patterns

Sample implementations for cloud design patterns found in the Azure Architecture Center.

azure cloud cost-optimization design-patterns operational-excellence performance-efficiency reliability security

Last synced: 08 Jul 2025

https://github.com/mojtabatajik/robber

Robber is open source tool for finding executables prone to DLL hijacking

candidate-dlls delphi dll-hijacking dlls security vulnerability-scanners

Last synced: 27 Jan 2026

https://github.com/JiaoXianjun/BTLE

Bluetooth Low Energy (BLE) packet sniffer and transmitter for both standard and non standard (raw bit) based on Software Defined Radio (SDR).

angle-of-arrival baseband bladerf ble bluetooth-low-energy dsp hackrf indoor-positioning packet-sniffer protocol-analyser protocol-parser rf sdr security sniffer software-defined-radio wireless-communication wireless-security wireless-sensor-networks

Last synced: 04 Apr 2025

https://github.com/mikesplain/openvas-docker

A Docker container for Openvas

docker docker-container openvas scan security shell

Last synced: 10 Jan 2026

https://github.com/hahwul/jwt-hack

๐Ÿ”ฉ jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce)

bugbounty cracking hacking hacktoberfest jwt payload-generator security testing-tools tool

Last synced: 26 Jan 2026

https://github.com/dradis/dradis-ce

Dradis Framework: Collaboration and reporting for IT Security teams

collaboration dradis dradis-framework infosec penetration-testing pentesting security security-audit

Last synced: 24 Jan 2026

https://github.com/0xZDH/o365spray

Username enumeration and password spraying tool aimed at Microsoft O365.

enumeration password-spray pentest pentesting-tools python python3 security security-tools

Last synced: 12 May 2025

https://github.com/frankmorgner/vsmartcard

umbrella project for emulation of smart card readers or smart cards

android c ccid emulation nfc pcsc python security smartcard smartcard-reader tizen-wearable

Last synced: 14 May 2025

https://github.com/webdigi/aws-vpn-server-setup

Setup your own private, secure, free* VPN on the Amazon AWS Cloud in 10 minutes. CloudFormation

aws aws-cloud cloudformation encryption ipsec ipsec-vpn l2tp lono security ssh-tunnel vpn vpn-client vpn-server vpn-service

Last synced: 08 Jul 2025

https://github.com/google/turbinia

Automation and Scaling of Digital Forensics Tools

cloud dfir forensics security security-automation

Last synced: 02 Apr 2025

https://github.com/coreos/vault-operator

Run and manage Vault on Kubernetes simply and securely

kubernetes operator operators security vault

Last synced: 29 Mar 2025

https://github.com/accrescent/accrescent

A novel Android app store focused on security, privacy, and usability

android appstore jetpack-compose kotlin material-design material3 privacy security

Last synced: 16 May 2025

https://github.com/tpm2-software/tpm2-tools

The source repository for the Trusted Platform Module (TPM2.0) tools

security signing tpm tpm2

Last synced: 14 May 2025

https://github.com/rocketshipapps/adblockfast

Adblock Fast is a faster ad blocker for Windows, Android, iOS, Chrome, and Opera.

android bash chrome-extension css firefox frontend gradle html http ios java javascript json maven nodejs npm objective-c security windows xml

Last synced: 15 May 2025

https://github.com/aquasecurity/chain-bench

An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

cis devsecops go golang misconfiguration open-policy-agent security security-tools software-supply-chain software-supply-chain-security vulnera

Last synced: 13 Oct 2025

https://github.com/allo-/ffprofile

A tool to create firefox profiles with personalized defaults.

django firefox privacy security

Last synced: 02 Apr 2026

https://github.com/byt3bl33d3r/witnessme

Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.

chromium headless-chrome osint python3 reconnaissance screenshots security security-tools web-inventory

Last synced: 16 May 2025

https://github.com/mhaskar/Octopus

Open source pre-operation C2 server based on python and powershell

c2 pentesting powershell python redteam security

Last synced: 24 Mar 2025

https://github.com/byt3bl33d3r/WitnessMe

Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.

chromium headless-chrome osint python3 reconnaissance screenshots security security-tools web-inventory

Last synced: 02 Apr 2025

https://github.com/Netflix/security-bulletins

Security Bulletins that relate to Netflix Open Source

security

Last synced: 12 Mar 2025

https://github.com/netflix/security-bulletins

Security Bulletins that relate to Netflix Open Source

security

Last synced: 27 Jan 2026

https://github.com/thesp0nge/dawnscanner

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

codereview cybersecurity hanami padrino rails ruby security security-audit sinatra vulnerabilities

Last synced: 15 May 2025

https://github.com/dinotools/dionaea

Home of the dionaea honeypot

dionaea honeypot security

Last synced: 16 May 2025

https://github.com/0xNazgul/Blockchain-Security-Audit-List

A list of Blockchain Security audit companies, solo auditors and location of public audits.

blockchain security

Last synced: 30 Mar 2025

https://github.com/DinoTools/dionaea

Home of the dionaea honeypot

dionaea honeypot security

Last synced: 16 Mar 2025

https://github.com/amnesica/KryptEY

Android keyboard for secure E2EE communication through the signal protocol in any messenger. Communicate securely and independent, regardless of the legal situation or whether messengers use E2EE

android android-keyboard chat-control chatcontrol chatkontrolle chatkontrolle-stoppen e2ee e2ee-encryption end-to-end-encryption input-method java keyboard libsignal messenger privacy security signal-android signal-protocol stop-scanning-me

Last synced: 05 Apr 2025

https://github.com/amnesica/kryptey

Android keyboard for secure E2EE communication through the signal protocol in any messenger. Communicate securely and independent, regardless of the legal situation or whether messengers use E2EE

android android-keyboard chat-control chatcontrol chatkontrolle chatkontrolle-stoppen e2ee e2ee-encryption end-to-end-encryption input-method java keyboard libsignal messenger privacy security signal-android signal-protocol stop-scanning-me

Last synced: 04 Apr 2025

https://github.com/tencent/habomalhunter

HaboMalHunter is a sub-project of Habo Malware Analysis System (https://habo.qq.com), which can be used for automated malware analysis and security assessment on the Linux system.

dynamic-analysis elf linux malware-analysis security static-analysis

Last synced: 12 Apr 2025

https://github.com/Tencent/HaboMalHunter

HaboMalHunter is a sub-project of Habo Malware Analysis System (https://habo.qq.com), which can be used for automated malware analysis and security assessment on the Linux system.

dynamic-analysis elf linux malware-analysis security static-analysis

Last synced: 11 Jul 2025

https://github.com/curiefense/curiefense

Curiefense is a unified, open source platform protecting cloud native applications.

bot-management botmanagement cloud-native cncf ddos ddos-protection envoyproxy microservices rate-limiter security session waf

Last synced: 01 May 2025

https://github.com/simpleidserver/SimpleIdServer

OpenID, OAuth 2.0, SCIM2.0, UMA2.0, FAPI, CIBA & OPENBANKING Framework for ASP.NET Core

ciba dotnet-core fapi identity oauth2 openid openid-providers scim2 security uma2

Last synced: 18 Apr 2025

https://github.com/damienbod/aspnet6identityserver4angularoidcflows

OpenID Connect Code Flow PKCE / Implicit Flow with Angular and ASP.NET Core 6 IdentityServer4

angular aspnet-core aspnetcore authentication authorization identity identityserver4 oauth2 oidc openid security sqlite typescript

Last synced: 12 Apr 2025

https://github.com/mhaskar/octopus

Open source pre-operation C2 server based on python and powershell

c2 pentesting powershell python redteam security

Last synced: 18 Jan 2026

https://github.com/damienbod/AspNet6IdentityServer4AngularOidcFlows

OpenID Connect Code Flow PKCE / Implicit Flow with Angular and ASP.NET Core 6 IdentityServer4

angular aspnet-core aspnetcore authentication authorization identity identityserver4 oauth2 oidc openid security sqlite typescript

Last synced: 09 Apr 2025

https://github.com/seemoo-lab/internalblue

Bluetooth experimentation framework for Broadcom and Cypress chips.

android ble bluetooth bluez broadcom cypress firmware ios linux macos security

Last synced: 16 May 2025

https://github.com/werkamsus/Lilith

Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

administration cplusplus cybersecurity entrepreneurship native security windows

Last synced: 15 Mar 2025

https://github.com/werkamsus/lilith

Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

administration cplusplus cybersecurity entrepreneurship native security windows

Last synced: 04 Apr 2025

https://github.com/dragokas/hijackthis

A free utility that finds malware, adware and other security threats

adware cleanup expert hijacking-methods malware portable pup scanner security toolbars tuneup unwanted

Last synced: 14 Feb 2026

https://github.com/usnistgov/OSCAL

Open Security Controls Assessment Language (OSCAL)

assessment authorization automation compliance json nist oscal schema security xml yaml

Last synced: 11 Apr 2025

https://github.com/usnistgov/oscal

Open Security Controls Assessment Language (OSCAL)

assessment authorization automation compliance json nist oscal schema security xml yaml

Last synced: 13 Apr 2025

https://github.com/intellabs/kafl

A fuzzer for full VM kernel/driver targets

firmware fuzzing grimoire intel kernel kvm qemu redqueen research security validation

Last synced: 27 Jan 2026

https://github.com/leonlatsch/photok

Encrypted Gallery App for Android

android android-app app encryption image kotlin photos safe security

Last synced: 09 Oct 2025

https://github.com/TypeError/domained

Multi Tool Subdomain Enumeration

bugbounty enumeration infosec security subdomains

Last synced: 02 Apr 2025

https://github.com/vu1nt0tal/yarb

ๆ–นไพฟ่Žทๅ–ๆฏๆ—ฅๅฎ‰ๅ…จ่ต„่ฎฏ็š„็ˆฌ่™ซๅ’ŒๆŽจ้€็จ‹ๅบ

bot rss security

Last synced: 15 May 2025

https://github.com/ronin-rb/ronin

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of code, exploits, payloads, etc, via 3rd-party git repositories.

cli console ctf-tool ctf-tools database hacking hacking-tools hacktoberfest infosec network-tools orm ronin ronin-rb ruby security security-tools

Last synced: 10 May 2025

https://github.com/agens-no/EllipticCurveKeyPair

Sign, verify, encrypt and decrypt using the Secure Enclave

elliptic-curves ios keychain keypair macos secure-enclave-processor security

Last synced: 08 Apr 2025

https://github.com/grapheneos/pdfviewer

Simple Android PDF viewer based on pdf.js and content providers. The app doesn't require any permissions. The PDF stream is fed into the sandboxed WebView without giving it access to content or files. CSP is used to enforce that the JavaScript and styling properties within the WebView are entirely static.

android grapheneos pdf pdf-viewer pdfjs security

Last synced: 15 May 2025

https://github.com/agens-no/ellipticcurvekeypair

Sign, verify, encrypt and decrypt using the Secure Enclave

elliptic-curves ios keychain keypair macos secure-enclave-processor security

Last synced: 12 Apr 2025

https://github.com/IntelLabs/kAFL

A fuzzer for full VM kernel/driver targets

firmware fuzzing grimoire intel kernel kvm qemu redqueen research security validation

Last synced: 11 Jul 2025

https://github.com/ghostsecurity/reaper

๐Ÿ’€ Don't fear the Reaper ๐Ÿ‘ป

agentic ai appsec automation bug-bounty fuzz fuzzing hacking owasp proxy security

Last synced: 12 Jan 2026

https://github.com/GossiTheDog/HiveNightmare

Exploit allowing you to read registry hives as non-admin on Windows 10 and 11

cybersecurity exploits security

Last synced: 20 Mar 2025