An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/genuinetools/audit

For auditing what collaborators, hooks, and deploy keys you have added on all your GitHub repositories.

auditing cli git github repo repos security

Last synced: 08 Jul 2025

https://github.com/JupiterOne/starbase

Graph-based security analysis for everyone

analysis aws azure cypher gcp graph hack hacktoberfest neo4j security

Last synced: 19 Apr 2025

https://github.com/tonybaloney/pycharm-security

Finds security holes in your Python projects from PyCharm and GitHub

devsecops hacktoberfest-accepted security security-automation static-analysis vulnerability

Last synced: 04 Apr 2025

https://github.com/scottyab/safetynethelper

SafetyNet Helper wraps the Google Play Services SafetyNet.API and verifies Safety Net API response with the Android Device Verification API.

android rootchecker safetynet-api safetynet-helper security

Last synced: 05 Apr 2025

https://github.com/wmal/linux-kodachi

Linux Kodachi is a security-focused operating system designed for users who value privacy, anonymity, and a secure computing experience. Developed by Warith Al Maawali, Kodachi provides all the tools necessary for anonymous online activities while maintaining ease of use.

cyber-security cybersecurity cybersecurity-education cybersecurity-tools linux privacy security

Last synced: 16 May 2025

https://github.com/chemidy/smallest-secured-golang-docker-image

Create the smallest and secured golang docker image based on scratch

distroless docker go golang hacktoberfest security

Last synced: 09 Apr 2025

https://github.com/Puliczek/CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera

๐ŸŽฉ ๐ŸคŸ๐Ÿป [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak - CVE-2022-0337

bugbounty bugbounty-writeups bugbountytips cve cve-2022-0337 cybersecurity exploit hacking payload pentest pentesting red-team security security-writeups writeups

Last synced: 02 Apr 2025

https://github.com/johackim/docker-hacklab

My personal hacklab, create your own.

docker hacklab security

Last synced: 06 Apr 2025

https://github.com/OpenCSPM/opencspm

Open Cloud Security Posture Management Engine

aws cloud cspm gcp kubernetes security security-audit

Last synced: 04 Apr 2025

https://github.com/casvisor/casvisor

An open-source security log auditing & RDP, VNC, SSH bastion platform, online demo: https://door.casvisor.com

audit auditing bastion casdoor casvisor database dbgate guacamole jumpbox jumpserver log logging rdp remote-control remote-desktop security ssh telnet vnc

Last synced: 05 Apr 2025

https://github.com/MindPointGroup/cloudfrunt

A tool for identifying misconfigured CloudFront domains

aws cloudfront security security-tools vulnerability-detection

Last synced: 23 Apr 2025

https://github.com/soxoj/counter-osint-guide-en

Comprehensive Counter OSINT and privacy guide (initially for CIS countries)

cis counter-osint guide osint privacy runet security

Last synced: 28 Jan 2026

https://github.com/fabston/little-snitch-blocklist

๐Ÿ›ก A malicious URL blocklist that protects you from advertisements, malwares, spams, statistics & trackers on both web browsing and applications.

adblocker ads blocklist littlesnitch mac malicious networking security spam

Last synced: 12 May 2025

https://github.com/ilpianista/arch-audit

A utility like pkg-audit for Arch Linux. Based on Arch Security Team data.

archlinux security

Last synced: 06 Apr 2025

https://github.com/InQuest/omnibus

The OSINT Omnibus (beta release)

iocs osint python security security-automation threat-intelligence

Last synced: 27 Mar 2025

https://github.com/ant4g0nist/susanoo

A REST API security testing framework.

pentest-tool pentesting python rest-api security security-tools

Last synced: 02 Apr 2025

https://github.com/jofpin/temcrypt

Evolutionary encryption framework based on scalable complexity over time

cryptography encryption javascript mechanism nodejs privacy security temcrypt

Last synced: 06 Apr 2025

https://github.com/paretoSecurity/pareto-mac

Automatically audit your Mac for basic security hygiene.

endpoint-security macos security swift swiftui

Last synced: 18 Apr 2025

https://github.com/lc/secretz

secretz, minimizing the large attack surface of Travis CI

hacktoberfest osint secrets security travis-ci

Last synced: 07 Apr 2025

https://github.com/brexhq/substation

Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.

automation aws logging monitoring observability security

Last synced: 16 May 2025

https://github.com/enlightn/security-checker

A PHP dependency vulnerabilities scanner based on the Security Advisories Database.

php security security-scanner vulnerability-scanner vulnerability-scanning

Last synced: 15 May 2025

https://github.com/fkie-cad/friTap

Simplifying SSL/TLS traffic analysis for researchers by making SSL decryption effortless.

android android-https-capture binary-analysis frida hooking https linux network-analysis network-capture network-forensics security security-audit ssl ssldump tcpdump tls

Last synced: 27 Mar 2025

https://github.com/zaproxy/action-baseline

A GitHub Action for running the ZAP Baseline scan

actions dast devsecops github-actions security

Last synced: 10 Apr 2025

https://github.com/ant4g0nist/Susanoo

A REST API security testing framework.

pentest-tool pentesting python rest-api security security-tools

Last synced: 13 Mar 2025

https://github.com/disclose/resources

Tools, data, and contact lists relevant to The disclose.io Project.

bug-bounty bugbounty certs infosec security vulnerability-disclosure

Last synced: 17 Jan 2026

https://github.com/jagaapple/next-secure-headers

Sets secure response headers for Next.js.

csp headers nextjs security

Last synced: 12 Apr 2025

https://github.com/padok-team/yatas

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

account assessment audit aws best-practices cli cloud configuration devsecops gcp hardening security

Last synced: 12 Jan 2026

https://github.com/sirAndros/KeePassWinHello

Quick unlock KeePass 2 database using biometrics with Windows Hello

biometrics keepass password-manager plugin security unlock windows-hello winhello

Last synced: 07 May 2025

https://github.com/mkalioby/django-mfa2

A Django app that handles MFA, it supports TOTP, U2F, FIDO2 U2F (Webauthn), Email Token and Trusted Devices

conda django django-packages django-web fido2 mfa python security totp webauthn

Last synced: 16 May 2025

https://github.com/MayankPandey01/Jira-Lens

Fast and customizable vulnerability scanner For JIRA written in Python

bugbounty jira jira-rest-api python3 scanner security security-tools vulnerability-scanners

Last synced: 12 Jul 2025

https://github.com/x011/secretpixel

SecretPixel is a cutting-edge steganography tool designed to securely conceal sensitive information within images. It stands out in the realm of digital steganography by combining advanced encryption, compression, and a seeded Least Significant Bit (LSB) technique to provide a robust solution for embedding data undetectably.

aes-256 aes-encryption cipher compression cryptography data-exfiltration encryption hacking hacking-tool hide-files hide-files-in-image image-steganography lsb-steganography privacy rsa-cryptography security security-tools steganography steganography-algorithms stego

Last synced: 16 May 2025

https://github.com/spacesiren/spacesiren

A honey token manager and alert system for AWS.

aws honeypot lambda security terraform

Last synced: 11 May 2025

https://github.com/cleanunicorn/karl

Monitor smart contracts deployed on blockchain and test against vulnerabilities with Mythril. It was presented at DEFCON 2019.

blockchain defcon defcon27 ethereum security smt symbolic-execution

Last synced: 12 Jan 2026

https://github.com/87owo/pyas

Antivirus software written in Python and C++ that blocks threats through deep learning and behavioral monitoring!

antivirus cnn cpp keras kernel lightgbm onnx pefile protect python scanner security tensorflow tools windows yara

Last synced: 18 Apr 2026

https://github.com/lydiahallie/advanced-web-dev-quiz

๐Ÿ”ฅ Repo related to my FrontendMasters course. An Advanced Web Dev Quiz that covers a wide range of the things web devs get to deal with on a daily basis.

csrf css html javascript performance rendering security web xss

Last synced: 06 Apr 2025

https://github.com/adamyordan/cve-2019-1003000-jenkins-rce-poc

Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)

cve cve-2019-1003000 exploit groovy information-security jenkins poc rce security security-1266

Last synced: 13 Oct 2025

https://github.com/cruise-automation/daytona

A Vault client, but for containers and servers.

aws gcp go kubernetes secrets secrets-management security vault

Last synced: 16 May 2025

https://github.com/vixentael/my-talks

List of my talks and workshops: security engineering, applied cryptography, secure software development

cryptography data-protection encryption infosec ios ios-swift mobile-development security security-engineering usability-engineering

Last synced: 06 Feb 2026

https://github.com/WMAL/Linux-Kodachi

Linux Kodachi is a security-focused operating system designed for users who value privacy, anonymity, and a secure computing experience. Developed by Warith Al Maawali, Kodachi provides all the tools necessary for anonymous online activities while maintaining ease of use.

cyber-security cybersecurity cybersecurity-education cybersecurity-tools linux privacy security

Last synced: 13 Mar 2025

https://github.com/tijme/angularjs-csti-scanner

Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.

angularjs angularjs-csti-scanner angularjs-sandbox-escape exploit sandbox-escape security tool vulnerability-scanners xss xss-scanners

Last synced: 06 Apr 2025

https://github.com/ezekg/git-hound

Git plugin that prevents sensitive data from being committed.

cli git git-plugin golang regular-expression security

Last synced: 10 Apr 2025

https://github.com/redcanaryco/chain-reactor

Chain Reactor is an open source framework for composing executables that simulate adversary behaviors and techniques on Linux endpoints.

adversary-simulation elf linux mitre mitre-attack security security-testing

Last synced: 16 May 2025

https://github.com/gellin/TeamViewer_Permissions_Hook_V1

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.

cplusplus cpp dll-injection hooking memory-hacking penetration-testing security teamviewer x86

Last synced: 12 Mar 2025

https://github.com/disclose/research-threats

Collection of legal threats against good faith Security Researchers; vulnerability disclosure gone wrong. A continuation of work started by @attritionorg

advisories cybersecurity legal news security vulnerability

Last synced: 17 Jan 2026

https://github.com/cloudflare/gortr

The RPKI-to-Router server used at Cloudflare

bgp cisco cloudflare cryptography juniper prometheus rpki security

Last synced: 06 Apr 2025

https://github.com/adysec/cf-mirror

AdySec CFๆ‹‰ๅนณ้•œๅƒ็ซ™ | ๅฎ˜ๆ–นๆบๅฏไฟกๅบฆๅ’Œ็จณๅฎšๆ€งๆœ€้ซ˜๏ผŒไฝ†ๅ›ฝๅ†…่ฎฟ้—ฎ้€Ÿๅบฆ่พƒๆ…ข๏ผŒ้€š่ฟ‡ไผ—็”Ÿๅนณ็ญ‰Cloudflare๏ผŒๅˆฉ็”จๅ…จ็ƒ็š„่พน็ผ˜่Š‚็‚น๏ผŒๅฐ†็”จๆˆท่ฏทๆฑ‚่ฝฌๅ‘ๅˆฐ็ฆป็”จๆˆท่ท็ฆปๆœ€่ฟ‘็š„่Š‚็‚น๏ผŒๅŒๆ—ถ็ผ“ๅญ˜้™ๆ€ๅ†…ๅฎนๅŠ ้€Ÿ๏ผŒๅ‡ๅฐ‘็ฝ‘็ปœๅปถ่ฟŸๅ’Œไธ‹่ฝฝ้€Ÿๅบฆ๏ผŒไฝฟ็”จCloudflare Workers้…็ฝฎๅไปฃๅฎž็Žฐ

archlinux centos cloudflare cloudflare-workers docker-ce fedora kali mirror mirrors openwrt pip pypi security serverless ubuntu worker

Last synced: 18 Mar 2025

https://github.com/Rizer0/Log-killer

Clear all your logs in [linux/windows] servers ๐Ÿ›ก๏ธ

hacking logs security server-management web-security

Last synced: 07 Apr 2025

https://github.com/google/kafel

A language and library for specifying syscall filtering policies.

linux seccomp-filter security syscalls

Last synced: 04 Apr 2025

https://github.com/badkeys/badkeys

Tool to find common vulnerabilities in cryptographic public keys

cryptography publickey rsa security

Last synced: 18 Feb 2026

https://github.com/lwindolf/lzone-cheat-sheets

A collection of sysadmin / DevOps / system architecture cheat sheets hosted on https://lzone.de

architecture automation cheatsheet cloud devops kubernetes linux security sysadmin

Last synced: 09 Apr 2026

https://github.com/liyupi/ceshiya

ๅ…่ดน็š„ไบคไบ’ๅผ็ฝ‘็ปœๅฎ‰ๅ…จ่‡ชๅญฆ็ฝ‘๏ผŒๅŠฉไฝ ๆˆไธบ็ฝ‘็ปœๅฎ‰ๅ…จ่พพไบบ๏ผ็บฏๅ‰็ซฏๅฎž็Žฐ๏ผŒ็ฎ€ๅ•ๆ˜“ๅญฆ~

ant-design ant-design-pro css frontend html javascript network programmer security typescript web

Last synced: 25 Dec 2025

https://github.com/mirleft/ocaml-tls

TLS in pure OCaml

mirageos ocaml security tls

Last synced: 08 Apr 2025

https://github.com/asamassekou10/ship-safe

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.

cli devscops npm owasp secrets security security-tools static-analysis

Last synced: 26 Apr 2026

https://github.com/l3yx/jdwp-codeifier

ๅŸบไบŽ jdwp-shellifier ็š„่ฟ›้˜ถJDWPๆผๆดžๅˆฉ็”จ่„šๆœฌ๏ผˆๅŠจๆ€ๆ‰ง่กŒJava/Jsไปฃ็ ๅนถ่Žทๅพ—ๅ›žๆ˜พ๏ผ‰

jdwp security

Last synced: 17 Jan 2026

https://github.com/rizer0/log-killer

Clear all your logs in [linux/windows] servers ๐Ÿ›ก๏ธ

hacking logs security server-management web-security

Last synced: 02 Apr 2025

https://github.com/valpackett/freepass

[DEPRECATED] password manager thing

masterpassword password password-manager security ssh

Last synced: 19 Mar 2025

https://github.com/adysec/mirror

AdySec CFๆ‹‰ๅนณ้•œๅƒ็ซ™ | ๅฎ˜ๆ–นๆบๅฏไฟกๅบฆๅ’Œ็จณๅฎšๆ€งๆœ€้ซ˜๏ผŒไฝ†ๅ›ฝๅ†…่ฎฟ้—ฎ้€Ÿๅบฆ่พƒๆ…ข๏ผŒ้€š่ฟ‡ไผ—็”Ÿๅนณ็ญ‰Cloudflare๏ผŒๅˆฉ็”จๅ…จ็ƒ็š„่พน็ผ˜่Š‚็‚น๏ผŒๅฐ†็”จๆˆท่ฏทๆฑ‚่ฝฌๅ‘ๅˆฐ็ฆป็”จๆˆท่ท็ฆปๆœ€่ฟ‘็š„่Š‚็‚น๏ผŒๅŒๆ—ถ็ผ“ๅญ˜้™ๆ€ๅ†…ๅฎนๅŠ ้€Ÿ๏ผŒๅ‡ๅฐ‘็ฝ‘็ปœๅปถ่ฟŸๅ’Œไธ‹่ฝฝ้€Ÿๅบฆ๏ผŒไฝฟ็”จCloudflare Workers้…็ฝฎๅไปฃๅฎž็Žฐ

archlinux centos cloudflare cloudflare-workers docker-ce fedora kali mirror mirrors openwrt pip pypi security serverless ubuntu worker

Last synced: 28 Nov 2025

https://github.com/EdOverflow/megplus

Automated reconnaissance wrapper โ€” TomNomNom's meg on steroids. [DEPRECATED]

bugbounty infosec recon reconnaissance security

Last synced: 10 May 2025

https://github.com/wizardforcel/web-hacking-101-zh

:book: [่ฏ‘] Web Hacking 101 ไธญๆ–‡็‰ˆ

101 book hack security web

Last synced: 17 Feb 2026

https://github.com/mc2-project/mc2

A Platform for Secure Analytics and Machine Learning

analytics cloud machine-learning privacy secure-analytics secure-learning security

Last synced: 15 Jan 2026

https://github.com/google/gcp_scanner

A comprehensive scanner for Google Cloud

automation gcp google-cloud-platform scanning-tool security

Last synced: 19 Apr 2025

https://github.com/patrickfav/armadillo

A shared preference implementation for confidential data in Android. Per default uses AES-GCM, BCrypt and HKDF as cryptographic primitives. Uses the concept of device fingerprinting combined with optional user provided passwords and strong password hashes.

aes-encryption aes-gcm android authenticated-encryption bcrypt crypto cryptography hkdf security sharedpreferences

Last synced: 05 Apr 2025

https://github.com/ispras/casr

Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity.

afl aflplusplus apport appsec coredump crash crash-reporting devsecops dynamic-analysis exploitable fuzzing gdb libfuzzer rust sdl security ssdlc testing triage vulnerability-management

Last synced: 12 Apr 2025

https://github.com/jonasgeiping/breaching

Breaching privacy in federated learning scenarios for vision and text

decentralized-learning federated-learning machine-learning privacy-audit pytorch security

Last synced: 06 Nov 2025

https://github.com/lesuisse/vue-dompurify-html

Safe replacement for the v-html directive

dom-xss dompurify security vue vuejs xss

Last synced: 14 May 2025

https://github.com/hashgraph-online/ai-plugin-scanner

Security and best-practices scanner for AI Plugins, covering Codex, Claude, Opencode, Gemini & more. Scores trust for plugins 0-100.

cli codex codex-plugins mcp plugin-scanner python scanner security

Last synced: 16 May 2026

https://github.com/codeintelligencetesting/jazzer.js

Coverage-guided, in-process fuzzing for Node.js

fuzzer fuzzing javascript nodejs security testing typescript

Last synced: 15 May 2025

https://github.com/scille/parsec-cloud

Open source Dropbox-like file sharing with full client encryption !

cloud dropbox file-sharing privacy security sharing-data

Last synced: 15 Jun 2026

https://github.com/j256/two-factor-auth

Two Factor Authentication Java code implementing the Time-based One-time Password Algorithm

java password security totp

Last synced: 05 Apr 2025

https://github.com/CodeIntelligenceTesting/jazzer.js

Coverage-guided, in-process fuzzing for Node.js

fuzzer fuzzing javascript nodejs security testing typescript

Last synced: 07 May 2025

https://github.com/gaprogman/owaspheaders.core

Inject OWASP recommended HTTP Headers for increased security in a single line

application-security aspnetcore http-header middleware nuget owasp security

Last synced: 14 May 2025

https://github.com/edoverflow/megplus

Automated reconnaissance wrapper โ€” TomNomNom's meg on steroids. [DEPRECATED]

bugbounty infosec recon reconnaissance security

Last synced: 02 Apr 2025