An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/ConsenSysDiligence/vscode-solidity-auditor

Solidity language support and visual security auditor for Visual Studio Code

security solidity vscode vscode-extension vscode-language vscode-theme

Last synced: 15 Apr 2025

https://github.com/chainguard-dev/osquery-defense-kit

Production-ready detection & response queries for osquery

defense osquery security threat-hunting

Last synced: 25 Jan 2026

https://github.com/jkctech/Telegram-Trilateration

Proof of concept for abusing Telegram's "People Near Me" feature and tracking people's location

exploit gps-coordinates gps-location nox nox-player privacy python security telegram vulnerability

Last synced: 20 Apr 2025

https://github.com/diversenok/TokenUniverse

An advanced tool for working with access tokens and Windows security policy.

access-tokens delphi native-api security security-tools windows windows-internals

Last synced: 09 Apr 2025

https://github.com/xfiftyone/STS2G

Struts2漏洞扫描利用工具 - Golang版. Struts2 Scanner Written in Golang

golang golang-application security struts2-exp vulnerability

Last synced: 14 Apr 2025

https://github.com/pocketpaw/pocketpaw

Your AI agent in 30 seconds. Not 30 hours. Self-hosted, open-source personal AI with desktop installer, multi-agent Command Center(Deep Work), and 7-layer security. Anthropic, OpenAI, or Ollama.

ai-agents cli jarvis-assistant multi-agent-systems ollama open-source personal-assistant python security self-hosted telegram-bot-ai-assistant

Last synced: 10 Mar 2026

https://github.com/aboutcode-org/vulnerablecode

A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/

cpe cve cvss nvd ossindex osv package-url purl security security-tools snyk vulndb vulnerability vulnerability-database vulnerability-databases vulnerability-detection vulnerability-identification vulnerability-scanners

Last synced: 14 May 2025

https://github.com/artginzburg/sudo-touchid

 Permanent TouchID support 👆 for `sudo`.

authentication bash cli macos security sudo terminal touchid

Last synced: 25 Oct 2025

https://github.com/rust-ammonia/ammonia

Repair and secure untrusted HTML

crates html-sanitization security web

Last synced: 13 May 2025

https://github.com/sdrapkin/securitydriven.inferno

:white_check_mark: .NET crypto done right. Professionally audited.

aead base32 base64 c-sharp crypto cryptography csharp dotnet encryption hash hkdf hmac kdf mac security totp

Last synced: 05 Apr 2025

https://github.com/stacklok/codegate

CodeGate: Security, Workspaces and Muxing for AI Applications, coding assistants, and agentic frameworks.

ai ai-gateway aisecurity artificial-intelligence claude cline codegen copilot developer-productivity developer-tools generative-ai ide jetbrains llm ollama openai privacy python security vscode

Last synced: 15 May 2025

https://github.com/sdrapkin/SecurityDriven.Inferno

:white_check_mark: .NET crypto done right. Professionally audited.

aead base32 base64 c-sharp crypto cryptography csharp dotnet encryption hash hkdf hmac kdf mac security totp

Last synced: 14 Mar 2025

https://github.com/Coldcard/firmware

❄️ Firmware and simulator for Coldcard Hardware Wallet

bitcoin bitcoin-wallet cryptocurrency cryptography security

Last synced: 26 Mar 2025

https://github.com/soxoj/counter-osint-guide-ru

Исчерпывающее руководство по приватности и контр-ОСИНТ для Рунета и всего СНГ 🇷🇺

cis counter-osint guide osint privacy runet security

Last synced: 27 Jan 2026

https://github.com/prompt-security/ps-fuzz

Make your GenAI Apps Safe & Secure :rocket: Test & harden your system prompt

ai ai-fuzzer fuzzer generative-ai llm llm-fuzzer security security-tools system-prompt-hardener

Last synced: 14 Jan 2026

https://github.com/shenril/sitadel

Web Application Security Scanner

penetration-testing python3 scanner-web security

Last synced: 02 Apr 2025

https://github.com/OWASP/www-project-kubernetes-top-ten

OWASP Foundation Web Respository

kubernetes owasp security

Last synced: 12 Apr 2025

https://github.com/liamg/scout

🔭 Lightweight URL fuzzer and spider: Discover a web server's undisclosed files, directories and VHOSTs

fuzzer hackthebox pentesting security url url-fuzzer

Last synced: 05 Apr 2025

https://github.com/the-viper-one/pentest-everything

A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.

active-directory active-directory-security bloodhound crto crtp ctf ctf-writeups ecpptv2 ejpt hacking hackthebox offensive-security oscp penetration-testing pentest-tools pentesting proving-grounds-writeups security tryhackme

Last synced: 27 Jan 2026

https://github.com/trailofbits/fickling

A Python pickling decompiler and static analyzer

machine-learning python security

Last synced: 04 Mar 2026

https://github.com/aws-samples/siem-on-amazon-opensearch-service

A solution for collecting, correlating and visualizing multiple types of logs to help investigate security incidents.

aws security

Last synced: 16 Apr 2025

https://github.com/mateusjunges/laravel-acl

This package helps you to associate users with permissions and permission groups with laravel framework

access-control access-management acl authentication authorization hacktoberfest laravel package php7 security

Last synced: 03 Oct 2025

https://github.com/nccgroup/tracy

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

browser-extension chrome chrome-extension firefox firefox-addon security security-tools xss xss-detection

Last synced: 04 Apr 2025

https://github.com/awslabs/automated-security-helper

ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.

aws awslabs iac sast sca scanner security

Last synced: 17 Feb 2026

https://github.com/JamesWoolfenden/pike

Pike is a tool for determining the permissions or policy required for IAC code

aws bridgecrew gcp iac policy security terraform

Last synced: 30 Mar 2025

https://github.com/jamesWoolfenden/pike

Pike is a tool for determining the permissions or policy required for IAC code

aws bridgecrew gcp iac policy security terraform

Last synced: 30 Mar 2025

https://github.com/jameswoolfenden/pike

Pike is a tool for determining the permissions or policy required for IAC code

aws bridgecrew gcp iac policy security terraform

Last synced: 25 Feb 2026

https://github.com/Ice1187/TW-Security-and-CTF-Resource

台灣資安 / CTF 學習資源整理

ctf security taiwan

Last synced: 02 Apr 2025

https://github.com/quillhash/quillaudit_auditor_roadmap

This repository contains a mindmap and stepwise resource to get started with Smart Contract Auditing. If you find anything missing or want to update existing resources, feel free to create a pull request.

blockchain ethereum evm security solidity

Last synced: 15 May 2025

https://github.com/kanidm/webauthn-rs

An implementation of webauthn components for Rustlang servers

security webauthn

Last synced: 23 Oct 2025

https://github.com/burtonqin/lockbud

Detect concurrency and memory bugs and possible panic locations in Rust projects

bug-detection rust security static-analyzer

Last synced: 30 Aug 2025

https://github.com/geerlingguy/ansible-role-firewall

Ansible Role - iptables Firewall configuration.

ansible centos debian fedora firewall iptables linux rhel role rules security ubuntu

Last synced: 14 Apr 2025

https://github.com/foxboron/ssh-tpm-agent

:computer: :key: ssh-agent for TPMs

go-tpm golang security ssh ssh-agent tpm tpm2

Last synced: 11 Jan 2026

https://github.com/FourCoreLabs/EDRHunt

Scan installed EDRs and AVs on Windows

infosec security security-tools

Last synced: 11 Jul 2025

https://github.com/MetaOSINT/MetaOSINT.github.io

A tool to quickly identify relevant, publicly-available open source intelligence ("OSINT") tools and resources, saving valuable time during investigations, research, and analysis.

cryptocurrency cybersecurity disinformation email facebook geoint geolocation instagram intelligence investigation news opsec osint search search-engine security social-media social-network twitter username

Last synced: 06 Aug 2025

https://github.com/honmashironeko/ARL-docker

基于ARL v2.6.2版本源码,生成docker镜像进行快速部署,同时提供七千多条指纹

arl cyber-security cyber-security-tool docker security security-tools

Last synced: 01 Mar 2026

https://github.com/Esonhugh/Attack_Code

文章 Attack Code 的详细全文。安全和开发总是具有伴生属性,尤其是云的安全方向,本篇文章是希望能帮助到读者的云安全入门材料。Full text of the article Attack Code. Security and development always have concomitant attributes, and this is especially true with the security direction of the cloud. This article is an introduction to cloud security that I hope will help readers.

article cloud cloud-security cloudsecurity introduction security

Last synced: 11 May 2025

https://github.com/esonhugh/attack_code

文章 Attack Code 的详细全文。安全和开发总是具有伴生属性,尤其是云的安全方向,本篇文章是希望能帮助到读者的云安全入门材料。Full text of the article Attack Code. Security and development always have concomitant attributes, and this is especially true with the security direction of the cloud. This article is an introduction to cloud security that I hope will help readers.

article cloud cloud-security cloudsecurity introduction security

Last synced: 05 Apr 2025

https://github.com/so87/CISSP-Study-Guide

study material used for the 2018 CISSP exam

cheatsheet cissp exam security study study-guide study-materials

Last synced: 11 Jul 2025

https://github.com/evilbytecode/goredops

🦫 | GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on the Go programming language, all is made for educational purpoeses only.

go golang hacking malware malware-development offensive-security red-team redteaming security windows

Last synced: 15 May 2025

https://github.com/shenril/Sitadel

Web Application Security Scanner

penetration-testing python3 scanner-web security

Last synced: 30 Mar 2025

https://github.com/podium/elixir-secure-coding

An interactive cybersecurity curriculum designed for enterprise use at software companies using Elixir

elixir elixir-lang elixir-phoenix livebook salus security security-education sobelow

Last synced: 28 Mar 2025

https://github.com/kevinburke/nacl

Pure Go implementation of the NaCL set of API's

curve25519 golang nacl secretbox security

Last synced: 16 May 2025

https://github.com/pcaversaccio/snekmate

State-of-the-art, highly opinionated, hyper-optimised, and secure 🐍Vyper smart contract building blocks.

ethereum evm library security smart-contracts vyper vyper-contracts

Last synced: 14 May 2025

https://github.com/twofas/2fas-ios

Source code for 2FAS iOS app

2fa ios security

Last synced: 17 Jan 2026

https://github.com/line/line-fido2-server

FIDO2(WebAuthn) server officially certified by FIDO Alliance and Relying Party examples.

example fido2 java passwordless relying-party security spring-boot webauthn

Last synced: 08 Oct 2025

https://github.com/Frissi0n/GTFONow

Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using GTFOBins.

ctf ctf-tools gtfobins hacking hackthebox offensive-security pentest pentesting post-exploitation privilege-escalation redteam security security-tools suid-binaries

Last synced: 11 Jun 2025

https://github.com/Hakky54/mutual-tls-ssl

🔐 Tutorial of setting up Security for your API with one way authentication with TLS/SSL and mutual authentication for a java based web server and a client with both Spring Boot. Different clients are provided such as Apache HttpClient, OkHttp, Spring RestTemplate, Spring WebFlux WebClient Jetty and Netty, the old and the new JDK HttpClient, the old and the new Jersey Client, Google HttpClient, Unirest, Retrofit, Feign, Methanol, vertx, Scala client Finagle, Featherbed, Dispatch Reboot, AsyncHttpClient, Sttp, Akka, Requests Scala, Http4s Blaze, Kotlin client Fuel, http4k, Kohttp and ktor. Also other server examples are available such as jersey with grizzly. Also gRPC, WebSocket and ElasticSearch examples are included

certificate certificate-authority certificate-signing-request encryption https java keystore keytool kotlin mutual-authentication mutual-tls openssl scala security server spring-boot ssl tls truststore two-way-ssl-authentication

Last synced: 10 May 2025

https://github.com/hakky54/mutual-tls-ssl

🔐 Tutorial of setting up Security for your API with one way authentication with TLS/SSL and mutual authentication for a java based web server and a client with both Spring Boot. Different clients are provided such as Apache HttpClient, OkHttp, Spring RestTemplate, Spring WebFlux WebClient Jetty and Netty, the old and the new JDK HttpClient, the old and the new Jersey Client, Google HttpClient, Unirest, Retrofit, Feign, Methanol, vertx, Scala client Finagle, Featherbed, Dispatch Reboot, AsyncHttpClient, Sttp, Akka, Requests Scala, Http4s Blaze, Kotlin client Fuel, http4k, Kohttp and ktor. Also other server examples are available such as jersey with grizzly. Also gRPC, WebSocket and ElasticSearch examples are included

certificate certificate-authority certificate-signing-request encryption https java keystore keytool kotlin mutual-authentication mutual-tls openssl scala security server spring-boot ssl tls truststore two-way-ssl-authentication

Last synced: 04 Apr 2025

https://github.com/ciscocsirt/gosint

The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).

golang ioc security threat-intelligence

Last synced: 14 Jan 2026

https://github.com/paragonie/csp-builder

Build Content-Security-Policy headers from a JSON file (or build them programmatically)

content-security-policy cross-site-scripting csp csp-builder csp-header easy-to-use http http-header json-configuration php secure-by-default security xss

Last synced: 14 May 2025

https://github.com/raphaelsc/am-i-affected-by-meltdown

Meltdown Exploit / Proof-of-concept / checks whether system is affected by Variant 3: rogue data cache load (CVE-2017-5754), a.k.a MELTDOWN.

exploit intelbug kaiser kpti meltdown poc pti security

Last synced: 05 Apr 2025

https://github.com/raphaelsc/Am-I-affected-by-Meltdown

Meltdown Exploit / Proof-of-concept / checks whether system is affected by Variant 3: rogue data cache load (CVE-2017-5754), a.k.a MELTDOWN.

exploit intelbug kaiser kpti meltdown poc pti security

Last synced: 21 Apr 2025

https://github.com/scheb/2fa

Two-factor authentication for Symfony applications 🔐

2fa security symfony symfony-bundle two-factor-authentication

Last synced: 04 Jan 2026

https://github.com/joshlarsen/aws-recon

Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

aws cli collection inventory scanner security

Last synced: 14 Mar 2025

https://github.com/phra/rustbuster

A Comprehensive Web Fuzzer and Content Discovery Tool

bug-bounty hacktoberfest pentesting reconnaissance security security-tools

Last synced: 05 Apr 2025

https://github.com/abhi-r3v0/Adhrit

Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.

analysis android android-security apk blackhat2020 blackhatarsenal dex enjarify ghera java mobile-security reverse-engineer security security-tools smali smalisca

Last synced: 08 May 2025

https://github.com/ciscocsirt/GOSINT

The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).

golang ioc security threat-intelligence

Last synced: 13 Mar 2025

https://github.com/wolfssl/wolfmqtt

wolfMQTT is a small, fast, portable MQTT client implementation, including support for TLS 1.3.

embedded iot iot-security mqqt-packet mqtt mqtt-client mqtt-library mqtt-sn mqtt-tls qos-0-2 quality-of-service security sensor-network tls tls13 tls13-support wolfmqtt wolfssl wolfssl-library

Last synced: 14 Apr 2025

https://github.com/wolfSSL/wolfMQTT

wolfMQTT is a small, fast, portable MQTT client implementation, including support for TLS 1.3.

embedded iot iot-security mqqt-packet mqtt mqtt-client mqtt-library mqtt-sn mqtt-tls qos-0-2 quality-of-service security sensor-network tls tls13 tls13-support wolfmqtt wolfssl wolfssl-library

Last synced: 05 Apr 2025

https://github.com/momenbasel/keyFinder

Keyfinder🔑 is a tool that let you find keys while surfing the web!

chrome-extension js pentesting pentesting-tools security

Last synced: 10 May 2025

https://github.com/kicksecure/security-misc

Kernel Hardening; Protect Linux User Accounts against Brute Force Attacks; Improve Entropy Collection; Strong Linux User Account Separation; Enhances Misc Security Settings - https://www.kicksecure.com/wiki/Security-misc

kernel-hardening kspp security

Last synced: 15 May 2025

https://github.com/lithnet/ad-password-protection

Active Directory password filter featuring breached password checking and custom complexity rules

active-directory lithnet-password-protection lpp password password-protection security

Last synced: 23 Jul 2025

https://github.com/yaklang/yaklang

A programming language exclusively designed for cybersecurity

cybersecurity dsl go security security-tools

Last synced: 28 Feb 2026

https://github.com/algolia/sup3rs3cretmes5age

Simple to use, simple to deploy, one time self destruct messaging service, with hashicorp vault as a backend

golang hashicorp-vault secrets security vault

Last synced: 19 Jun 2025

https://github.com/momenbasel/keyfinder

Keyfinder🔑 is a tool that let you find keys while surfing the web!

chrome-extension js pentesting pentesting-tools security

Last synced: 05 Apr 2025

https://github.com/LewisArdern/bXSS

bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.

blueteam bugbounty bxss cross-site-scripting infosec security xss

Last synced: 02 Apr 2025

https://github.com/patrickfav/bcrypt

A Java standalone implementation of the bcrypt password hash function. Based on the Blowfish cipher it is the default password hash algorithm for OpenBSD and other systems including some Linux distributions. Includes a CLI Tool.

bcrypt bcrypt-library bycrypt-password cli crypto hash java java-library kdf password-hash security

Last synced: 14 May 2025

https://github.com/ex0dus-0x/fuzzable

Framework for Automating Fuzzable Target Discovery with Static Analysis.

binary-analysis fuzzing reverse-engineering security security-tools static-analysis

Last synced: 12 Apr 2025

https://github.com/hakky54/sslcontext-kickstart

🔐 A lightweight high level library for configuring a http client or server based on SSLContext or other properties such as TrustManager, KeyManager or Trusted Certificates to communicate over SSL TLS for one way authentication or two way authentication provided by the SSLFactory. Support for Java, Scala and Kotlin based clients with examples. Available client examples are: Apache HttpClient, OkHttp, Spring RestTemplate, Spring WebFlux WebClient Jetty and Netty, the old and the new JDK HttpClient, the old and the new Jersey Client, Google HttpClient, Unirest, Retrofit, Feign, Methanol, Vertx, Scala client Finagle, Featherbed, Dispatch Reboot, AsyncHttpClient, Sttp, Akka, Requests Scala, Http4s Blaze, Kotlin client Fuel, http4k Kohttp and Ktor. Also gRPC, WebSocket and ElasticSearch examples are included

android certificate der encryption https java keymanagerfactory keystore kotlin mutual-authentication p12 p7b pem scala security ssl sslcontext tls trustmanagerfactory truststore

Last synced: 11 Jan 2026

https://github.com/intility/fastapi-azure-auth

Easy and secure implementation of Azure Entra ID (previously AD) for your FastAPI APIs 🔒 B2C, single- and multi-tenant support.

anyio asgi asyncio authentication azure azure-active-directory azure-ad azuread fastapi oauth2 oidc openapi openid openidconnect python security trio

Last synced: 14 May 2025

https://github.com/JanssenProject/jans

An enterprise identity and access management platform-- Janssen is a distribution of standards-based, developer friendly, components that are engineered to work together in any cloud. #OAuth #OpenID #FIDO

access-management api iam identity kubernetes oauth2 openid-connect security sso

Last synced: 04 Apr 2025

https://github.com/tejado/authorizer

Authorizer is a Password Manager for Android. It emulates an HID keyboard over USB and enters your credentials on your target device. Additionally it supports OTP :key::mobile_phone_off:

android auto-type bluetooth bluetooth-hid encryption gpg gpg-encryption hid keyboard-emulation otp password-manager password-store security smartphone usb usb-hid

Last synced: 04 Apr 2025

https://github.com/tejado/Authorizer

Authorizer is a Password Manager for Android. It emulates an HID keyboard over USB and enters your credentials on your target device. Additionally it supports OTP :key::mobile_phone_off:

android auto-type bluetooth bluetooth-hid encryption gpg gpg-encryption hid keyboard-emulation otp password-manager password-store security smartphone usb usb-hid

Last synced: 23 Mar 2025

https://github.com/mehulj94/Radium

Python logger with multiple features.

keylogger python security

Last synced: 02 Apr 2025

https://github.com/iqiyi/qnsm

QNSM is network security monitoring framework based on DPDK.

anti-ddos dpdk kernel-bypass network-analysis network-security security suricata

Last synced: 05 Apr 2025

https://github.com/neilalexander/sigmavpn

Light-weight, secure and modular VPN solution which makes use of NaCl encryption (also available for Android using jnacl in "sigmavpn-android")

c libsodium nacl security tunnel vpn

Last synced: 06 Oct 2025