An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/idaholab/malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

arkime cybersecurity infosec network-security network-traffic-analysis networksecurity networktrafficanalysis opensearch opensearch-dashboards pcap security suricata zeek

Last synced: 13 Mar 2025

https://github.com/center-for-threat-informed-defense/security-stack-mappings

🚨ATTENTION🚨 The Security Stack Mappings have migrated to the Center’s Mappings Explorer project. See README below. This repository is kept here as an archive.

aws azure cloud gcp mitre-attack security

Last synced: 31 Mar 2025

https://github.com/johnnykv/heralding

Credentials catching honeypot

deception honeypot security security-tools

Last synced: 16 May 2025

https://github.com/discord/access

Access, a centralized portal for employees to transparently discover, request, and manage their access for all internal systems needed to do their jobs

access authorization okta permissions rbac security

Last synced: 08 Apr 2025

https://github.com/adysec/ARL

ARL 资产侦察灯塔系统(可运行,添加指纹,提高并发,升级工具及系统,无限制修改版) | ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。

arl cyber-security flask fofa python scan security security-tools shodan tools

Last synced: 31 Oct 2025

https://github.com/meetrevision/revision-tool

A tool to personalize ReviOS to your needs

ame-wizard performance revios security tool tweaking usability windows

Last synced: 23 Jan 2026

https://github.com/adysec/arl

ARL 资产侦察灯塔系统(可运行,添加指纹,提高并发,升级工具及系统,无限制修改版) | ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。

arl cyber-security flask fofa python scan security security-tools shodan tools

Last synced: 08 Apr 2025

https://github.com/curtbraz/PhishAPI

Comprehensive Web Based Phishing Suite for Rapid Deployment and Real-Time Alerting!

cyberaware cybersecurity hacking infosec pentesting phish phishing phishing-kit security socialengineering

Last synced: 11 Jul 2025

https://github.com/grt1st/wooyun_search

乌云公开漏洞、知识库搜索 search from wooyun.org

security wooyun

Last synced: 08 Jan 2026

https://github.com/plazmaz/lnkup

Generates malicious LNK file payloads for data exfiltration

data-exfiltration lnk lnk-payloads microsoft ntlm payload penetration-testing pentesting security usb windows

Last synced: 08 Apr 2025

https://github.com/Fuzzapi/API-fuzzer

API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities

gem ruby ruby-gem rubygem security vulnerability

Last synced: 07 Apr 2025

https://github.com/fuzzapi/api-fuzzer

API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities

gem ruby ruby-gem rubygem security vulnerability

Last synced: 09 Apr 2025

https://github.com/yuawn/ntu-computer-security

台大 計算機安全 - Pwn 簡報、影片、作業題目與解法 - Computer Security Fall 2019 @ CSIE NTU Taiwan

binary-exploitation course csie ctf education exploitation exploits ntu pwn reverse-engineering security

Last synced: 23 Jul 2025

https://github.com/yuawn/NTU-Computer-Security

台大 計算機安全 - Pwn 簡報、影片、作業題目與解法 - Computer Security Fall 2019 @ CSIE NTU Taiwan

binary-exploitation course csie ctf education exploitation exploits ntu pwn reverse-engineering security

Last synced: 02 Apr 2025

https://github.com/JFreegman/SpicyPass

A light-weight password manager with a focus on simplicity and security

password-generator password-manager password-safety password-store security security-tools spicy-software

Last synced: 22 Nov 2025

https://github.com/snyk/vulnerabilitydb

Snyk's public vulnerability database

infosec security snyk vulndb vulnerabilities vulnerability-databases

Last synced: 02 Apr 2025

https://github.com/hillu/local-log4j-vuln-scanner

Simple local scanner for vulnerable log4j instances

cve-2019-17571 cve-2021-44228 log4j2 log4shell scanner security security-tools

Last synced: 05 Apr 2025

https://github.com/jamesturk/django-honeypot

🍯 Generic honeypot utilities for use in django projects.

django honeypot python security

Last synced: 14 May 2025

https://github.com/aaaddress1/Windows-APT-Warfare

著作《Windows APT Warfare:惡意程式前線戰術指南》各章節技術實作之原始碼內容

apt hackers hacking malware security windows

Last synced: 11 Jul 2025

https://github.com/egebalci/deoptimizer

Evasion by machine code de-optimization.

antivirus detection evasion malware redteaming security snort suricata yara

Last synced: 13 Apr 2025

https://github.com/santatic/web2attack

Web hacking framework with tools, exploits by python

hacking hacking-tool hacking-tools hackingtools pentesting python security

Last synced: 25 Oct 2025

https://github.com/charlie-belmer/nosqli

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

mongodb nosql nosql-injection security security-automation security-scanner security-tools sqlinjection

Last synced: 06 Apr 2025

https://github.com/sap-samples/machine-learning-diff-private-federated-learning

Simulate a federated setting and run differentially private federated learning.

differential-privacy federated-learning machine-learning sample sample-code security

Last synced: 11 Apr 2025

https://github.com/Charlie-belmer/nosqli

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

mongodb nosql nosql-injection security security-automation security-scanner security-tools sqlinjection

Last synced: 02 Apr 2025

https://github.com/spatie/laravel-ciphersweet

Use Ciphersweet in your Laravel project

laravel php privacy security

Last synced: 14 May 2025

https://github.com/jfreegman/spicypass

A light-weight password manager with a focus on simplicity and security

password-generator password-manager password-safety password-store security security-tools spicy-software

Last synced: 06 Apr 2025

https://github.com/jasonlovesdoggo/caddy-defender

Caddy module to block or manipulate requests originating from AIs or cloud services trying to train on your websites

ai ai-blocker blocker blockers caddy caddy-plugin caddyserver chatgpt filter ip-blacklist ip-filtering security waf web-security

Last synced: 30 Dec 2025

https://github.com/byt3bl33d3r/red-baron

Automate creating resilient, disposable, secure and agile infrastructure for Red Teams

infrastructure infrastructure-as-code red-teams security security-tools terraform terraform-modules

Last synced: 30 Sep 2025

https://github.com/flatt-security/shisho

Lightweight static analyzer for several programming languages

code-analysis devsecops go rust security static-analysis terraform terraform-security

Last synced: 30 Mar 2025

https://github.com/x13a/Duress

Duress password trigger

android kotlin security

Last synced: 02 Apr 2025

https://github.com/x13a/duress

Duress password trigger

android kotlin security

Last synced: 05 Apr 2025

https://github.com/psecio/parse

Parse: A Static Security Scanner

php scanner security

Last synced: 16 May 2025

https://github.com/phalcon/vokuro

Sample application for Phalcon Framework (Acl, Auth, Security)

acl demo phalcon phalcon-framework php sample security tutorial vokuro

Last synced: 13 May 2025

https://github.com/shmakov/honeypot

Low interaction honeypot that displays real time attacks

data-visualization honeypot logs nodejs security ssh tail telnet

Last synced: 02 Apr 2025

https://github.com/bndw/pick

A secure and easy-to-use CLI password manager for macOS and Linux

aes-gcm chacha20-poly1305 cli crypto linux macos openpgp password password-manager pbkdf2 scrypt security

Last synced: 15 Mar 2025

https://github.com/Shmakov/Honeypot

Low interaction honeypot that displays real time attacks

data-visualization honeypot logs nodejs security ssh tail telnet

Last synced: 06 Apr 2025

https://github.com/ionescu007/simpleator

Simpleator ("Simple-ator") is an innovative Windows-centric x64 user-mode application emulator that leverages several new features that were added in Windows 10 Spring Update (1803), also called "Redstone 4", with additional improvements that were made in Windows 10 October Update (1809), aka "Redstone 5".

containerization containers emulator hyper-v malware malware-analysis operating-systems reverse-engineering security virtualization

Last synced: 15 Oct 2025

https://github.com/teivah/designdeck

An Open-Source Collection of 230+ Flash Cards to Help You Succeed in Your System Design Interview and More 💯

cache cloud database http interview interview-preparation kafka leetcode network reliability scalability security system-design

Last synced: 03 Apr 2025

https://github.com/paretosecurity/pareto-mac

Automatically audit your Mac for basic security hygiene.

endpoint-security macos security swift swiftui

Last synced: 16 May 2025

https://github.com/ullaakut/camerattack

An attack tool designed to remotely disable CCTV camera streams (like in spy movies)

attack camera cctv csec ddos hack rtsp security

Last synced: 11 Apr 2025

https://github.com/damienbod/aspnetcorehybridflowwithapi

Different ASP.NET Core applications using OpenID Connect Hybrid flow Code Flow, Code Flow with PKCE, JWT APIs, MFA examples

asp-net-core asp-net-mvc hybrid-flow jwt oauth2 oidc openid pkce security token

Last synced: 04 Jan 2026

https://github.com/damienbod/AspNetCoreHybridFlowWithApi

Different ASP.NET Core applications using OpenID Connect Hybrid flow Code Flow, Code Flow with PKCE, JWT APIs, MFA examples

asp-net-core asp-net-mvc hybrid-flow jwt oauth2 oidc openid pkce security token

Last synced: 09 Apr 2025

https://github.com/symfony/security-acl

Symfony Security ACL Component

acl component php security symfony symfony-component

Last synced: 14 May 2025

https://github.com/aidantwoods/go-paseto

Platform-Agnostic Security Tokens implementation in Golang.

go go-paseto golang paseto security token

Last synced: 16 May 2025

https://github.com/whgojp/JavaSecLab

​ JavaSecLab是一款综合型Java漏洞平台,提供相关漏洞缺陷代码、修复代码、漏洞场景、审计SINK点、安全编码规范,覆盖多种漏洞场景,友好用户交互UI……

code-audit devsecops java sdl security

Last synced: 31 Oct 2025

https://github.com/lovasoa/bad_json_parsers

Exposing problems in json parsers of several programming languages.

json json-parser parser security

Last synced: 05 Apr 2025

https://github.com/gcarq/inox-patchset

Inox patchset tries to provide a minimal Chromium based browser with focus on privacy by disabling data transmission to Google.

browser chromium patchset privacy security

Last synced: 03 Oct 2025

https://github.com/Ullaakut/camerattack

An attack tool designed to remotely disable CCTV camera streams (like in spy movies)

attack camera cctv csec ddos hack rtsp security

Last synced: 06 Apr 2025

https://github.com/dolegi/lockdown.sh

Lockdown your linux install. The simple zero config linux hardening script

debian harden linux lockdown lynis security

Last synced: 07 Apr 2025

https://github.com/bytedance/vArmor

vArmor is a cloud native container sandbox system based on AppArmor/BPF/Seccomp. It also includes multiple built-in protection rules that are ready to use out of the box.

apparmor apparmor-profiles bpf containers kubernetes lsm policy sandbox seccomp security

Last synced: 30 Apr 2025

https://github.com/bytedance/varmor

vArmor is a cloud native container sandbox system based on AppArmor/BPF/Seccomp. It also includes multiple built-in protection rules that are ready to use out of the box.

apparmor apparmor-profiles bpf containers kubernetes lsm policy sandbox seccomp security

Last synced: 16 May 2025

https://github.com/anchore/anchore

This project is deprecated. Work is now done on https://github.com/anchore/syft and https://github.com/anchore/grype for local-host Software Bill of Materials and vulnerability scanning tools.

containers docker python security

Last synced: 30 Dec 2025

https://github.com/jwilk/python-afl

American Fuzzy Lop fork server and instrumentation for pure-Python code

fuzzing security

Last synced: 08 Apr 2025

https://github.com/ionescu007/Simpleator

Simpleator ("Simple-ator") is an innovative Windows-centric x64 user-mode application emulator that leverages several new features that were added in Windows 10 Spring Update (1803), also called "Redstone 4", with additional improvements that were made in Windows 10 October Update (1809), aka "Redstone 5".

containerization containers emulator hyper-v malware malware-analysis operating-systems reverse-engineering security virtualization

Last synced: 30 Mar 2025

https://github.com/ruisiang/pow-shield

Project dedicated to fight Layer 7 DDoS with proof of work, with an additional WAF and controller. Completed with full set of features and containerized for rapid and lightweight deployment.

cybersecurity ddos ddos-mitigation ddos-protection koa2 netsec network-security nodejs proof-of-work proxy-server security spam-filtering spam-protection typescript waf

Last synced: 16 May 2025

https://github.com/emproof-com/nyxstone

Nyxstone: assembly / disassembly library based on LLVM, implemented in C++ with Rust and Python bindings, maintained by emproof.com

aarch64 arm assembly disassembly infosec mips powerpc reverse-engineering risc-v security thumb x86 x86-64

Last synced: 15 May 2025

https://github.com/slowmist/eos-bp-nodes-security-checklist

EOS bp nodes security checklist(EOS超级节点安全执行指南)

blockchain checklist eosio hacking security

Last synced: 11 Apr 2025

https://dave-theunsub.github.io/clamtk

An easy to use, light-weight, on-demand virus scanner for Linux systems

clamtk deb gtk gtk3 gui linux linux-desktop perl python retired rpm scanner security

Last synced: 02 Mar 2025

https://github.com/hawkeyesec/scanner-cli

A project security/vulnerability/risk scanning tool

ci docker nodejs npm ruby security

Last synced: 01 Apr 2025

https://github.com/dave-theunsub/clamtk

An easy to use, light-weight, on-demand virus scanner for Linux systems

clamtk deb gtk gtk3 gui linux linux-desktop perl python retired rpm scanner security

Last synced: 05 Apr 2025

https://github.com/sofianehamlaoui/pentest-notes

Collection of Pentest Notes and Cheatsheets from a lot of repos (SofianeHamlaoui,dostoevsky,mantvydasb,adon90,BriskSec)

cheatsheets offensive-security penetration-testing penetration-testing-tools pentesting security security-audit security-tools sofianehamlaoui

Last synced: 12 Mar 2025

https://github.com/do-know/crypt-le

Crypt::LE - Let's Encrypt / Buypass / ZeroSSL and other ACME-servers client and library in Perl for obtaining free SSL certificates (inc. generating RSA/ECC keys and CSRs). HTTP/DNS verification is supported out of the box, EAB (External Account Binding) supported, easily extended with plugins, easily dockerized.

acme acme-client acme-v2 certificate crypt crypt-le dns docker docker-ssl ecc ecdsa free-ssl-certificates https perl pfx rsa security ssl windows-ssl zerossl

Last synced: 06 Apr 2025

https://github.com/do-know/Crypt-LE

Crypt::LE - Let's Encrypt / Buypass / ZeroSSL and other ACME-servers client and library in Perl for obtaining free SSL certificates (inc. generating RSA/ECC keys and CSRs). HTTP/DNS verification is supported out of the box, EAB (External Account Binding) supported, easily extended with plugins, easily dockerized.

acme acme-client acme-v2 certificate crypt crypt-le dns docker docker-ssl ecc ecdsa free-ssl-certificates https perl pfx rsa security ssl windows-ssl zerossl

Last synced: 04 Apr 2025

https://github.com/genuinetools/pepper

A tool for performing actions on GitHub repos or a single repo.

cli git github repo repos security

Last synced: 12 Apr 2025

https://github.com/idaholab/Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

arkime cybersecurity infosec network-security network-traffic-analysis networksecurity networktrafficanalysis opensearch opensearch-dashboards pcap security suricata zeek

Last synced: 30 Mar 2025

https://github.com/keyshade-xyz/keyshade

Realtime secret and configuration management tool, with the best in class security and seamless integration support

cli configuration-management devsecops fullstack good-first-issue hacktoberfest javascript nestjs nextjs reactjs saas secret-management secrets-manager security turborepo typescript

Last synced: 05 Jan 2026

https://github.com/mchev/banhammer

Banhammer for Laravel offers a simple way to ban any Model by ID, UUID and by IP or Country.

access autorization ban block countries ip laravel middleware package php restrict security trait user

Last synced: 22 Jan 2026

https://github.com/SofianeHamlaoui/Pentest-Notes

Collection of Pentest Notes and Cheatsheets from a lot of repos (SofianeHamlaoui,dostoevsky,mantvydasb,adon90,BriskSec)

cheatsheets offensive-security penetration-testing penetration-testing-tools pentesting security security-audit security-tools sofianehamlaoui

Last synced: 12 Jul 2025

https://github.com/elliotkillick/qvm-create-windows-qube

Spin up new Windows qubes quickly, effortlessly and securely on Qubes OS

automation cybersecurity infosec privacy qubes qubes-os security virtualization whonix windows windows-10

Last synced: 16 May 2025

https://github.com/ElliotKillick/qvm-create-windows-qube

Spin up new Windows qubes quickly, effortlessly and securely on Qubes OS

automation cybersecurity infosec privacy qubes qubes-os security virtualization whonix windows windows-10

Last synced: 09 Apr 2025

https://github.com/cryptofinlabs/audit-checklist

A Solidity smart contract auditing checklist

ethereum security solidity

Last synced: 15 Mar 2025

https://github.com/jserv/talks

schedule and materials about my presentations

aarch64 arm c-programming guts kernel linux microcontroller open-source rtos security

Last synced: 16 May 2025

https://github.com/GrapheneOS/platform_manifest

Repo manifest for the GrapheneOS mobile privacy and security hardening project.

android grapheneos privacy security

Last synced: 11 Jul 2025

https://github.com/lifepillar/CSVKeychain

Import/export between Apple Keychain.app and plain CSV file.

apple csv export import keepass keychain password security

Last synced: 15 Mar 2025

https://github.com/SAP/credential-digger

A Github scanning tool that identifies hardcoded credentials while filtering the false positive data through machine learning models :lock:

credentials machine-learning python regex scanner secret security security-tools

Last synced: 11 Jul 2025

https://github.com/lifepillar/csvkeychain

Import/export between Apple Keychain.app and plain CSV file.

apple csv export import keepass keychain password security

Last synced: 28 Feb 2025

https://github.com/Consensys/UniversalToken

Implementation of Universal Token for Assets and Payments

asset codefi erc1400 erc20 ethereum finance security sto token universal

Last synced: 09 May 2025

https://github.com/Skiller9090/Lucifer

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build Automation Modules To Speed Up Your Cyber Security Life

automation automation-framework cyber-security cybersec cybersecurity enumeration exfiltration framework hacking hacking-framework hacking-tool modular modules pentest-tool pentesting privilege-escalation python security security-tools

Last synced: 12 Jul 2025

https://github.com/LyleMi/papers

Academic papers and articles that I read related to web hacking, fuzzing, etc. / 阅读过的Web安全方向、模糊测试方向的一些论文与阅读笔记

awesome fuzzing papers read-papers reading-notes security

Last synced: 11 Jul 2025