An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/ovh/debian-cis

PCI-DSS compliant Debian 10/11/12 hardening

audit cis debian pci-dss security shell

Last synced: 16 May 2025

https://github.com/EnableSecurity/sipvicious

SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks against PBX systems especially through identification, scanning, extension enumeration and password cracking.

audit-sip hacking-tools password-cracker security security-tools sip svcrack svcrash svmap svwar voip war-dial

Last synced: 14 Mar 2025

https://github.com/nyxiereal/XToolbox

XToolBox - A collection of 150+ Windows 10/11 optimization and tweaking apps!

debloat debloater declutter decrapify linux python python-3 python3 security toolbox toolkit windows windows-10 windows-11 windows-11-debloat

Last synced: 04 Sep 2025

https://github.com/vincentcox/stacoan

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

bugbounty mobile-security security security-tools static-code-analysis

Last synced: 04 Apr 2025

https://github.com/JLospinoso/gargoyle

A memory scanning evasion technique

assembly memory-analysis pic rop-gadgets security x86

Last synced: 11 Jul 2025

https://github.com/spatie/laravel-csp

Set content security policy headers in a Laravel app

csp http laravel request security

Last synced: 24 Jan 2026

https://github.com/ullaakut/gorsair

Gorsair gives root access on remote docker containers that expose their APIs

docker infosec netsec nmap penetration-testing pentesting security

Last synced: 02 Apr 2025

https://github.com/Ullaakut/Gorsair

Gorsair gives root access on remote docker containers that expose their APIs

docker infosec netsec nmap penetration-testing pentesting security

Last synced: 03 May 2025

https://github.com/hluwa/Wallbreaker

🔨 Break Java Reverse Engineering form Memory World!

android debug debugger frida java python reverseengineering security

Last synced: 27 Mar 2025

https://github.com/SmartContractSecurity/SWC-registry

Smart Contract Weakness Classification and Test Cases

ethereum security smart-contracts

Last synced: 17 Apr 2025

https://github.com/sethvargo/ratchet

A tool for securing CI/CD workflows with version pinning.

cicd dependency security

Last synced: 16 May 2025

https://github.com/vincentcox/StaCoAn

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

bugbounty mobile-security security security-tools static-code-analysis

Last synced: 19 Mar 2025

https://github.com/Netflix/Fido

security

Last synced: 04 Apr 2025

https://github.com/sektioneins/pcc

PHP Secure Configuration Checker

configuration php security

Last synced: 27 Apr 2025

https://github.com/OWASP/DevSecOpsGuideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

devsecops owasp security shift-left

Last synced: 18 Jul 2025

https://github.com/brunty/awesome-checker-services

✅ List of links to the various checkers out there on the web for sites, domains, security etc.

checker dns hacktoberfest list load-testing mail-configuration mobile-friendly security seo speed website website-performance

Last synced: 16 Jan 2026

https://github.com/simpleidserver/simpleidserver

OpenID, OAuth 2.0, SCIM2.0, UMA2.0, FAPI, CIBA & OPENBANKING Framework for ASP.NET Core

ciba dotnet-core fapi identity oauth2 openid openid-providers scim2 security uma2

Last synced: 15 May 2025

https://github.com/chromium/hstspreload.org

:lock: Chromium's HSTS preload list submission website.

chrome chromium hsts hstspreload https security

Last synced: 13 Apr 2025

https://github.com/legit-labs/legitify

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

ci devops devsecops github gitlab golang sdlc-security security security-scanner supply-chain-security

Last synced: 15 May 2025

https://github.com/prateek147/DVIA-v2

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security enthusiasts/professionals or students to test their iOS penetration testing skills in a legal environment. This project is developed and maintained by @prateekg147. The vulnerabilities and solutions covered in this app are tested up to iOS 11. The current version is writen in Swift and has the following vulnerabilities.

ios-swift jailbreak mobile-app security

Last synced: 12 Jul 2025

https://github.com/Legit-Labs/legitify

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

ci devops devsecops github gitlab golang sdlc-security security security-scanner supply-chain-security

Last synced: 01 Apr 2025

https://github.com/tankerhq/sdk-js

Tanker client-side encryption SDK for JavaScript

cryptography encryption end-to-end javascript privacy sdk security tanker

Last synced: 14 May 2025

https://github.com/jvoisin/snuffleupagus

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

c elephant hardening php php-module php7 security security-hardening

Last synced: 07 Jan 2026

https://github.com/TankerHQ/sdk-js

Tanker client-side encryption SDK for JavaScript

cryptography encryption end-to-end javascript privacy sdk security tanker

Last synced: 23 Mar 2025

https://github.com/netheril96/securefs

Filesystem in userspace (FUSE) with transparent authenticated encryption

authentication cloud crypto cryptography encryption filesystem filesystems fuse fuse-filesystem security

Last synced: 21 Oct 2025

https://github.com/0xbug/SQLiScanner

Automatic SQL injection with Charles and sqlmap api

autoscan scanner security security-audit security-vulnerability sqlmap sqlmap-webui sqlmapapi

Last synced: 02 Apr 2025

https://github.com/firefart/stunner

Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers.

exploit misconfiguration security stun testing tool turn webrtc

Last synced: 15 May 2025

https://github.com/jiaoxianjun/btle

Bluetooth Low Energy (BLE) packet sniffer and transmitter for both standard and non standard (raw bit) based on Software Defined Radio (SDR).

angle-of-arrival baseband bladerf ble bluetooth-low-energy dsp hackrf indoor-positioning packet-sniffer protocol-analyser protocol-parser rf sdr security sniffer software-defined-radio wireless-communication wireless-security wireless-sensor-networks

Last synced: 15 May 2025

https://github.com/google/turbinia

Automation and Scaling of Digital Forensics Tools

cloud dfir forensics security security-automation

Last synced: 26 Apr 2026

https://github.com/snyk/zip-slip-vulnerability

Zip Slip Vulnerability (Arbitrary file write through archive extraction)

security vulnerabilities

Last synced: 27 Jan 2026

https://github.com/google/paranoid_crypto

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

cryptography security

Last synced: 18 Apr 2025

https://github.com/mspnp/cloud-design-patterns

Sample implementations for cloud design patterns found in the Azure Architecture Center.

azure cloud cost-optimization design-patterns operational-excellence performance-efficiency reliability security

Last synced: 08 Jul 2025

https://github.com/mojtabatajik/robber

Robber is open source tool for finding executables prone to DLL hijacking

candidate-dlls delphi dll-hijacking dlls security vulnerability-scanners

Last synced: 27 Jan 2026

https://github.com/JiaoXianjun/BTLE

Bluetooth Low Energy (BLE) packet sniffer and transmitter for both standard and non standard (raw bit) based on Software Defined Radio (SDR).

angle-of-arrival baseband bladerf ble bluetooth-low-energy dsp hackrf indoor-positioning packet-sniffer protocol-analyser protocol-parser rf sdr security sniffer software-defined-radio wireless-communication wireless-security wireless-sensor-networks

Last synced: 04 Apr 2025

https://github.com/mikesplain/openvas-docker

A Docker container for Openvas

docker docker-container openvas scan security shell

Last synced: 10 Jan 2026

https://github.com/dradis/dradis-ce

Dradis Framework: Collaboration and reporting for IT Security teams

collaboration dradis dradis-framework infosec penetration-testing pentesting security security-audit

Last synced: 24 Jan 2026

https://github.com/hahwul/jwt-hack

🔩 jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce)

bugbounty cracking hacking hacktoberfest jwt payload-generator security testing-tools tool

Last synced: 26 Jan 2026

https://github.com/0xZDH/o365spray

Username enumeration and password spraying tool aimed at Microsoft O365.

enumeration password-spray pentest pentesting-tools python python3 security security-tools

Last synced: 12 May 2025

https://github.com/frankmorgner/vsmartcard

umbrella project for emulation of smart card readers or smart cards

android c ccid emulation nfc pcsc python security smartcard smartcard-reader tizen-wearable

Last synced: 14 May 2025

https://github.com/webdigi/aws-vpn-server-setup

Setup your own private, secure, free* VPN on the Amazon AWS Cloud in 10 minutes. CloudFormation

aws aws-cloud cloudformation encryption ipsec ipsec-vpn l2tp lono security ssh-tunnel vpn vpn-client vpn-server vpn-service

Last synced: 08 Jul 2025

https://github.com/coreos/vault-operator

Run and manage Vault on Kubernetes simply and securely

kubernetes operator operators security vault

Last synced: 29 Mar 2025

https://github.com/accrescent/accrescent

A novel Android app store focused on security, privacy, and usability

android appstore jetpack-compose kotlin material-design material3 privacy security

Last synced: 16 May 2025

https://github.com/tpm2-software/tpm2-tools

The source repository for the Trusted Platform Module (TPM2.0) tools

security signing tpm tpm2

Last synced: 14 May 2025

https://github.com/rocketshipapps/adblockfast

Adblock Fast is a faster ad blocker for Windows, Android, iOS, Chrome, and Opera.

android bash chrome-extension css firefox frontend gradle html http ios java javascript json maven nodejs npm objective-c security windows xml

Last synced: 15 May 2025

https://github.com/allo-/ffprofile

A tool to create firefox profiles with personalized defaults.

django firefox privacy security

Last synced: 02 Apr 2026

https://github.com/aquasecurity/chain-bench

An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

cis devsecops go golang misconfiguration open-policy-agent security security-tools software-supply-chain software-supply-chain-security vulnera

Last synced: 13 Oct 2025

https://github.com/byt3bl33d3r/witnessme

Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.

chromium headless-chrome osint python3 reconnaissance screenshots security security-tools web-inventory

Last synced: 16 May 2025

https://github.com/unipacker/unipacker

Automatic and platform-independent unpacker for Windows binaries based on emulation

debugger dumper emulation packers pefile python reverse-engineering security unicorn-engine unpacker windows

Last synced: 18 Apr 2026

https://github.com/byt3bl33d3r/WitnessMe

Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.

chromium headless-chrome osint python3 reconnaissance screenshots security security-tools web-inventory

Last synced: 02 Apr 2025

https://github.com/mhaskar/Octopus

Open source pre-operation C2 server based on python and powershell

c2 pentesting powershell python redteam security

Last synced: 24 Mar 2025

https://github.com/netflix/security-bulletins

Security Bulletins that relate to Netflix Open Source

security

Last synced: 27 Jan 2026

https://github.com/Netflix/security-bulletins

Security Bulletins that relate to Netflix Open Source

security

Last synced: 12 Mar 2025

https://github.com/thesp0nge/dawnscanner

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

codereview cybersecurity hanami padrino rails ruby security security-audit sinatra vulnerabilities

Last synced: 15 May 2025

https://github.com/dinotools/dionaea

Home of the dionaea honeypot

dionaea honeypot security

Last synced: 16 May 2025

https://github.com/0xNazgul/Blockchain-Security-Audit-List

A list of Blockchain Security audit companies, solo auditors and location of public audits.

blockchain security

Last synced: 30 Mar 2025

https://github.com/DinoTools/dionaea

Home of the dionaea honeypot

dionaea honeypot security

Last synced: 16 Mar 2025

https://github.com/vdjagilev/nmap-formatter?tab=readme-ov-file

A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot), sqlite, excel and d2-lang. Simply put it's nmap converter.

bounty csv d2lang go golang graphviz html json markdown nmap pentesting port-scanner port-scanning scan scanner security security-tools sqlite xml xml-parsing

Last synced: 08 Jun 2026

https://github.com/amnesica/kryptey

Android keyboard for secure E2EE communication through the signal protocol in any messenger. Communicate securely and independent, regardless of the legal situation or whether messengers use E2EE

android android-keyboard chat-control chatcontrol chatkontrolle chatkontrolle-stoppen e2ee e2ee-encryption end-to-end-encryption input-method java keyboard libsignal messenger privacy security signal-android signal-protocol stop-scanning-me

Last synced: 04 Apr 2025

https://github.com/amnesica/KryptEY

Android keyboard for secure E2EE communication through the signal protocol in any messenger. Communicate securely and independent, regardless of the legal situation or whether messengers use E2EE

android android-keyboard chat-control chatcontrol chatkontrolle chatkontrolle-stoppen e2ee e2ee-encryption end-to-end-encryption input-method java keyboard libsignal messenger privacy security signal-android signal-protocol stop-scanning-me

Last synced: 05 Apr 2025

https://github.com/tencent/habomalhunter

HaboMalHunter is a sub-project of Habo Malware Analysis System (https://habo.qq.com), which can be used for automated malware analysis and security assessment on the Linux system.

dynamic-analysis elf linux malware-analysis security static-analysis

Last synced: 12 Apr 2025

https://github.com/curiefense/curiefense

Curiefense is a unified, open source platform protecting cloud native applications.

bot-management botmanagement cloud-native cncf ddos ddos-protection envoyproxy microservices rate-limiter security session waf

Last synced: 01 May 2025

https://github.com/Tencent/HaboMalHunter

HaboMalHunter is a sub-project of Habo Malware Analysis System (https://habo.qq.com), which can be used for automated malware analysis and security assessment on the Linux system.

dynamic-analysis elf linux malware-analysis security static-analysis

Last synced: 11 Jul 2025

https://github.com/simpleidserver/SimpleIdServer

OpenID, OAuth 2.0, SCIM2.0, UMA2.0, FAPI, CIBA & OPENBANKING Framework for ASP.NET Core

ciba dotnet-core fapi identity oauth2 openid openid-providers scim2 security uma2

Last synced: 18 Apr 2025

https://github.com/damienbod/aspnet6identityserver4angularoidcflows

OpenID Connect Code Flow PKCE / Implicit Flow with Angular and ASP.NET Core 6 IdentityServer4

angular aspnet-core aspnetcore authentication authorization identity identityserver4 oauth2 oidc openid security sqlite typescript

Last synced: 12 Apr 2025

https://github.com/damienbod/AspNet6IdentityServer4AngularOidcFlows

OpenID Connect Code Flow PKCE / Implicit Flow with Angular and ASP.NET Core 6 IdentityServer4

angular aspnet-core aspnetcore authentication authorization identity identityserver4 oauth2 oidc openid security sqlite typescript

Last synced: 09 Apr 2025

https://github.com/mhaskar/octopus

Open source pre-operation C2 server based on python and powershell

c2 pentesting powershell python redteam security

Last synced: 18 Jan 2026

https://github.com/werkamsus/Lilith

Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

administration cplusplus cybersecurity entrepreneurship native security windows

Last synced: 15 Mar 2025

https://github.com/seemoo-lab/internalblue

Bluetooth experimentation framework for Broadcom and Cypress chips.

android ble bluetooth bluez broadcom cypress firmware ios linux macos security

Last synced: 16 May 2025

https://github.com/werkamsus/lilith

Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

administration cplusplus cybersecurity entrepreneurship native security windows

Last synced: 04 Apr 2025

https://github.com/dragokas/hijackthis

A free utility that finds malware, adware and other security threats

adware cleanup expert hijacking-methods malware portable pup scanner security toolbars tuneup unwanted

Last synced: 14 Feb 2026

https://github.com/usnistgov/OSCAL

Open Security Controls Assessment Language (OSCAL)

assessment authorization automation compliance json nist oscal schema security xml yaml

Last synced: 11 Apr 2025

https://github.com/intellabs/kafl

A fuzzer for full VM kernel/driver targets

firmware fuzzing grimoire intel kernel kvm qemu redqueen research security validation

Last synced: 27 Jan 2026

https://github.com/leonlatsch/photok

Encrypted Gallery App for Android

android android-app app encryption image kotlin photos safe security

Last synced: 09 Oct 2025

https://github.com/vu1nt0tal/yarb

方便获取每日安全资讯的爬虫和推送程序

bot rss security

Last synced: 15 May 2025

https://github.com/TypeError/domained

Multi Tool Subdomain Enumeration

bugbounty enumeration infosec security subdomains

Last synced: 02 Apr 2025