An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/saturneric/GpgFrontend

A free, open-source, robust yet user-friendly, compact and cross-platform tool for OpenPGP encryption. It stands out as an exceptional GUI frontend for the modern GnuPG (gpg).

communication crypto decrypt digital-signature dsa ecc ecdh ecdsa encrypt encryption-decryption gpg openpgp rsa security security-tools signature signature-verification

Last synced: 26 Mar 2025

https://github.com/hxsecurity/terraformgoat

TerraformGoat is HXSecurity research lab's "Vulnerable by Design" multi cloud deployment tool.

aws-security azure-security cloud-security cloudsecurity gcp gcp-security kubernetes-security security terraform

Last synced: 05 Apr 2025

https://github.com/life4/enc

🔑🔒 A modern and friendly CLI alternative to GnuPG: generate and download keys, encrypt, decrypt, and sign text and files, and more.

cli cryptography decryption encryption gnupg go golang gpg keybase pgp rsa-cryptography security signature

Last synced: 05 Apr 2025

https://github.com/harmveenstra/powershellisfun

Repository with the scripts that I have used in my blogs on https://powershellisfun.com. If you like these, please sponsor this project using the Sponsor button below or buy me a coffee :) https://www.buymeacoffee.com/powershellisfun

365 active-directory endpoint-manager exchange fun hyper-v intune microsoft networking powershell powershell-script sandbox scripts security security-audit security-tools server windows windowssandbox winget

Last synced: 15 May 2025

https://github.com/nette/forms

📝 Generating, validating and processing secure forms in PHP. Handy API, fully customizable, server & client side validation and mature design.

forms html javascript nette nette-framework php safety security validation

Last synced: 29 Apr 2025

https://github.com/HarmVeenstra/Powershellisfun

Repository with the scripts that I have used in my blogs on https://powershellisfun.com. If you like these, please sponsor this project using the Sponsor button below or buy me a coffee :) https://www.buymeacoffee.com/powershellisfun

365 active-directory endpoint-manager exchange fun hyper-v intune microsoft networking powershell powershell-script sandbox scripts security security-audit security-tools server windows windowssandbox winget

Last synced: 09 Apr 2025

https://github.com/archstrike/archstrike

An Arch Linux repository for security professionals and enthusiasts. Done the Arch Way and optimized for i686, x86_64, ARMv6, ARMv7 and ARMv8.

arch-linux arch-pkgbuilds archstrike armv6 armv7 armv8 distro hackers hacking linux linux-distribution odroid-c2 penetration-testing pentesting raspberry-pi repository security security-audit security-professionals tools

Last synced: 04 Apr 2025

https://github.com/andryou/scriptsafe

a browser extension to bring security and privacy to chrome, firefox, and opera

blacklist block browser chrome control extension fingerprinting firefox javascript noscript opera privacy protection scriptsafe security tracking whitelist

Last synced: 04 Apr 2025

https://github.com/llsoftsec/llsoftsecbook

Low-Level Software Security for Compiler Developers

book compiler compiler-development security

Last synced: 04 Apr 2025

https://github.com/ultrasecurity/darkside

Tool Information Gathering & social engineering Write By [Python,JS,PHP]

hack hack-tool js penetration-testing pentest-tool php python security

Last synced: 10 Apr 2025

https://github.com/armijnhemel/binaryanalysis-ng

Binary Analysis Next Generation (BANG)

compliance licensecompliance reverseengineering security

Last synced: 15 May 2025

https://github.com/jedisct1/edgedns

A high performance DNS cache designed for Content Delivery Networks

cache cdn dns rust security

Last synced: 05 Apr 2025

https://github.com/Quillhash/QuillAudit_Auditor_Roadmap

This repository contains a mindmap and stepwise resource to get started with Smart Contract Auditing. If you find anything missing or want to update existing resources, feel free to create a pull request.

blockchain ethereum evm security solidity

Last synced: 08 Apr 2025

https://github.com/escape-technologies/graphql-armor

🛡️ The missing GraphQL security security layer for Apollo GraphQL and Yoga / Envelop servers 🛡️

apollo apollo-server cybersecurity envelop graphql hacktoberfest middleware security security-tools typescript

Last synced: 14 May 2025

https://github.com/Escape-Technologies/graphql-armor

🛡️ The missing GraphQL security security layer for Apollo GraphQL and Yoga / Envelop servers 🛡️

apollo apollo-server cybersecurity envelop graphql hacktoberfest middleware security security-tools typescript

Last synced: 04 May 2025

https://github.com/nnsee/fileless-elf-exec

Execute ELF files without dropping them on disk

elf linux python redteam security security-tools

Last synced: 12 Jan 2026

https://github.com/google/capillary

Capillary is a library to simplify the sending of end-to-end encrypted push messages from Java-based application servers to Android clients.

android crypto cryptography end-to-end-encryption java privacy security

Last synced: 06 Apr 2025

https://github.com/libaibaia/cloudSec

云安全利用工具-云平台AK/SK-WEB利用工具,添加AK/SK自动检测资源,无需手动执行,支持云服务器、存储桶、数据库操作

cloudsec security security-tools webapp

Last synced: 07 Sep 2025

https://github.com/tar-ser/automated-liquid-staking-tool-cross-chain-rwa-optimizer

Professional tool for automating trading on DEX (Ethereum, BSC, Solana, AVAX and 15+ networks) with a focus on liquid staking, cross-chain arbitrage and investing in RWA (Real World Assets).

1inch aave algorithmic-trading arbitrage curve-finance defi dex ethereum finance gas-optimization high-frequency-trading layer2 liquidity makerdao multichain security solana staking trading-strategies zk-proof

Last synced: 02 Mar 2025

https://github.com/sevagas/swap_digger

swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux user credentials, web forms credentials, web forms emails, http basic authentication, Wifi SSID and keys, etc.

dfir forensics hacking post-exploitation security

Last synced: 05 Apr 2025

https://github.com/ArchStrike/ArchStrike

An Arch Linux repository for security professionals and enthusiasts. Done the Arch Way and optimized for i686, x86_64, ARMv6, ARMv7 and ARMv8.

arch-linux arch-pkgbuilds archstrike armv6 armv7 armv8 distro hackers hacking linux linux-distribution odroid-c2 penetration-testing pentesting raspberry-pi repository security security-audit security-professionals tools

Last synced: 30 Apr 2025

https://github.com/tar-ser/automated-liquidity-management-and-security-for-solana-projects

is a powerful tool for projects with >$100k liquidity. It provides automatic pool rebalancing, hacker protection, real-time analytics and cross-chain management.

anchor-framework blockchain cross-chain cryptocurrency dao defi liquidity-pools marinade orca raydium rust security solana solend spl-tokens staking tokenomics web3 wormhole yield-farming

Last synced: 03 Mar 2025

https://github.com/houqp/sqlvet

Go fearless SQL. Sqlvet performs static analysis on raw SQL queries in your Go code base.

golang linter security sql static-analysis

Last synced: 09 Apr 2025

https://github.com/trimstray/technical-whitepapers

Collection of IT whitepapers, presentations, pdfs; hacking, web app security, db, reverse engineering and more; EN/PL.

bsd databases devops hacking linux manuals pdfs pentesters security security-researchers sysadmin whitepapers

Last synced: 06 Apr 2025

https://github.com/ivpn/ios-app

Official IVPN iOS app

ios ivpn privacy security swift vpn vpn-client

Last synced: 09 Apr 2025

https://github.com/Paradoxis/Flask-Unsign

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

bruteforce ctf ctf-tools penetration-testing pentesting security security-tools

Last synced: 12 Jul 2025

https://github.com/minio/kes

[Deprecated] Key Encryption Server

cryptography encryption kms modern scale secure-by-default security

Last synced: 20 Jun 2025

https://github.com/modzero/mod0BurpUploadScanner

HTTP file upload scanner for Burp Proxy

burp extension fileupload multipart scanner security uploadscanner

Last synced: 19 Apr 2025

https://github.com/The-Viper-One/Pentest-Everything

A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.

active-directory active-directory-security bloodhound crto crtp ctf ctf-writeups ecpptv2 ejpt hacking hackthebox offensive-security oscp penetration-testing pentest-tools pentesting proving-grounds-writeups security tryhackme

Last synced: 20 Apr 2025

https://github.com/JPCERTCC/MalConfScan

Volatility plugin for extracts configuration data of known malware

forensics malware memory python security volatility

Last synced: 30 Mar 2025

https://github.com/the-viper-one/pentest-everything

A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.

active-directory active-directory-security bloodhound crto crtp ctf ctf-writeups ecpptv2 ejpt hacking hackthebox offensive-security oscp penetration-testing pentest-tools pentesting proving-grounds-writeups security tryhackme

Last synced: 15 Mar 2025

https://github.com/jpcertcc/malconfscan

Volatility plugin for extracts configuration data of known malware

forensics malware memory python security volatility

Last synced: 05 Apr 2025

https://github.com/bage2014/study

Java全栈工程师学习笔记;Spring、shiro、CAS、oauth2单点登录;cache 、Redis; web 安全及解决思路;redis、mq、quartz、docker;Docker各种组件实践等;mybatis、spring、spring boot实践;分布式锁;基于分库分表等等;Java full-stack engineer study notes; Spring, shiro, CAS, oauth2 single sign-on; cache, Redis; web security and solutions; redis, mq, quartz, docker; Docker various component practices, etc.;

cache cas java jwt mq nginx redis security spring spring-boot sso swagger tomcat web

Last synced: 11 Jul 2025

https://github.com/git-artes/gr-tempest

An implementation of TEMPEST en GNU Radio

gnu-radio sdr security tempest

Last synced: 14 Mar 2025

https://github.com/0x4d31/burpa

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application Security Testing (DAST).

automation burp burpsuite devops python security security-automation security-scanner security-tools web-security

Last synced: 05 Dec 2025

https://github.com/0x4D31/burpa

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application Security Testing (DAST).

automation burp burpsuite devops python security security-automation security-scanner security-tools web-security

Last synced: 11 Apr 2025

https://github.com/stanfrbd/cyberbro

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

blueteam cti cyber-threat-intelligence cybersecurity dfir docker hash incident-response infosec ioc ipinfo osint osint-python python security security-tools threat threat-hunting threat-intelligence virustotal

Last synced: 16 Jan 2026

https://github.com/modzero/mod0burpuploadscanner

HTTP file upload scanner for Burp Proxy

burp extension fileupload multipart scanner security uploadscanner

Last synced: 02 Apr 2025

https://github.com/710leo/zvuldrill

Web漏洞演练平台

security websecurity

Last synced: 05 Apr 2025

https://github.com/genuinetools/bpfd

Framework for running BPF programs with rules on Linux as a daemon. Container aware.

bpf cli containers docker ebpf kernel linux security tracing

Last synced: 16 May 2025

https://github.com/710leo/ZVulDrill

Web漏洞演练平台

security websecurity

Last synced: 02 May 2025

https://github.com/google/clusterfuzzlite

ClusterFuzzLite - Simple continuous fuzzing that runs in CI.

ci continuous-integration fuzz-testing fuzzing security vulnerabilities

Last synced: 07 Apr 2025

https://github.com/sigstore/sigstore

Common go library shared across sigstore services and clients

cosign go golang security sigstore supply-chain

Last synced: 29 Mar 2025

https://github.com/netflix-skunkworks/aardvark

Aardvark is a multi-account AWS IAM Access Advisor API

aws security

Last synced: 16 May 2025

https://github.com/pwnfoo/ntlmrecon

Enumerate information from NTLM authentication enabled web endpoints 🔎

blackarch cybersecurity enumeration hacking hacking-tools ntlm ntlmssp osint recon reconnaissance redteam security tools

Last synced: 14 Dec 2025

https://google.github.io/clusterfuzzlite/

ClusterFuzzLite - Simple continuous fuzzing that runs in CI.

ci continuous-integration fuzz-testing fuzzing security vulnerabilities

Last synced: 07 May 2025

https://github.com/FuzzingLabs/octopus

Security Analysis tool for WebAssembly module (wasm) and Blockchain Smart Contracts (BTC/ETH/NEO/EOS)

blockchain call-flow-analysis control-flow-analysis disassembler eos ethereum evm-bytecode neo security security-analysis smart-contracts wasm webassembly

Last synced: 18 Apr 2025

https://github.com/boxlite-ai/boxlite

Embedded sandbox for running AI agents.

ai-agents containers sandbox security serverless virtualization

Last synced: 16 Jan 2026

https://github.com/skerkour/kerkour.com

(Ab)using technology for fun & profit. Programming, Hacking & Entrepreneurship @ https://kerkour.com

blog blogging crypto cryptography encryption go golang programming rust rust-lang security web

Last synced: 04 Apr 2025

https://github.com/nix-community/vulnix

Vulnerability (CVE) scanner for Nix/NixOS.

cve nix nixos security vulnerabilities vulnerability

Last synced: 04 Apr 2025

https://github.com/miscreant/meta

Meta-repository for Miscreant: misuse-resistant symmetric encryption library with AES-SIV (RFC 5297) and AES-PMAC-SIV support

aead aes cryptography key-wrapping nonce-misuse-attacks security siv streaming-encryption

Last synced: 20 Mar 2025

https://github.com/zoph-io/MAMIP

[MAMIP] Monitor AWS Managed IAM Policies Changes

aws changes iam managed monitor policies security

Last synced: 30 Mar 2025

https://github.com/cilium/cilium-cli

CLI to install, manage & troubleshoot Kubernetes clusters running Cilium

cilium ebpf kubernetes networking observability security

Last synced: 13 Apr 2025

https://github.com/dev-sec/cis-docker-benchmark

CIS Docker Benchmark - InSpec Profile

cis-docker-benchmark docker hardening inspec security

Last synced: 14 Mar 2025

https://github.com/in-toto/witness

Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.

attestation security security-tools supply-chain verification

Last synced: 15 May 2025

https://github.com/paragonie/chronicle

Public append-only ledger microservice built with Slim Framework

append-only blake2b chain cryptography hash hash-chain knowledge php proof sapient security security-tools

Last synced: 04 Apr 2025

https://github.com/spatie/crypto

Encrypt and decrypt data using private/public keys

php security

Last synced: 14 May 2025

https://github.com/santoru/shcheck

A basic tool to check security headers of a website

headers http https response security

Last synced: 08 Apr 2025

https://github.com/jchambers/java-otp

A one-time password (HOTP/TOTP) library for Java

2fa hotp java one-time-password otp security totp two-factor-authentication

Last synced: 13 Apr 2025

https://github.com/daniel-cues/NMapGUI

Advanced Graphical User Interface for NMap

cybersecurity monitoring network-analysis nmap security sysadmin

Last synced: 02 Apr 2025

https://github.com/pwnfoo/NTLMRecon

Enumerate information from NTLM authentication enabled web endpoints 🔎

blackarch cybersecurity enumeration hacking hacking-tools ntlm ntlmssp osint recon reconnaissance redteam security tools

Last synced: 11 Jul 2025

https://github.com/bmarsh9/gapps

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking. https://gapps.darkbanner.com

27002 asvs cis18 cmmc compliance csc grc hipaa iso27001 nist nist-csf nist800-53 owasp owasp-top-10 pci pci-dss security soc2

Last synced: 05 Apr 2025

https://github.com/AabyssZG/AWD-Guide

从零学习AWD比赛指导手册以及AWD脚本整理

awd awd-tools ctf ctf-framework ctf-tools security

Last synced: 05 Apr 2025

https://github.com/pyupio/pyup

A tool to update your project's dependencies on GitHub. Runs on pyup.io, comes with a command line interface.

dependency dependency-manager security security-tools security-vulnerability

Last synced: 16 May 2025

https://github.com/step-security/github-actions-goat

GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

actions attack-simulation attack-simulator devsecops hacking security

Last synced: 15 May 2025

https://github.com/aabysszg/awd-guide

从零学习AWD比赛指导手册以及AWD脚本整理

awd awd-tools ctf ctf-framework ctf-tools security

Last synced: 05 Apr 2025