An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/petermosmans/security-scripts

A collection of security related Python and Bash shell scripts. Analyze hosts on generic security vulnerabilities. Wrapper around popular tools like nmap (portscanner), nikto (webscanner) and testssl.sh (SSL/TLS scanner)

nikto nmap python security security-scanner security-tools ssl testssl

Last synced: 07 Apr 2025

https://github.com/Orange-Cyberdefense/grepmarx

A source code static analysis platform for AppSec enthusiasts.

appsec sast sca security

Last synced: 19 Jun 2026

https://github.com/fbonalair/traefik-crowdsec-bouncer

A http service to verify request and bounce them according to decisions made by CrowdSec.

container-image crowdsec crowdsec-bouncer go golang security traefik traefik-v2 webapp

Last synced: 02 Apr 2025

https://github.com/BlessedRebuS/Krawl

Krawl is a customizable lightweight cloud native web deception server and anti-crawler that creates fake web applications with low-hanging vulnerabilities and realistic, randomly generated decoy data

anti-crawling blue-team cloud-native crawler cybersecurity deception honeypot kubernetes security self-hosted spider web

Last synced: 11 Feb 2026

https://github.com/azat-io/actions-up

🌊 Interactive CLI tool to update GitHub Actions to latest versions with SHA pinning

actions cli dependencies github-actions security workflow

Last synced: 07 Oct 2025

https://github.com/kevalpatel2106/PasscodeView

PasscodeView is an Android Library to easily and securely authenticate user with PIN code or using the fingerprint scanner.

android-library authentication fingerprint-authentication pattern-lock pincode security

Last synced: 21 Apr 2025

https://github.com/iantrich/restriction-card

🔒 Apply restrictions to Lovelace cards

custom-card home-assistant lovelace security

Last synced: 02 Mar 2026

https://github.com/ThreatUnknown/jsubfinder

jsubfinder searches webpages for javascript & analyzes them for hidden subdomains and secrets (wip).

bugbounty pentesting proxy security security-tools

Last synced: 19 Apr 2025

https://github.com/lazywinadmin/Monitor-ADGroupMembership

PowerShell script to monitor Active Directory groups and send an email when someone is changing the membership

active-directory hacktoberfest monitoring powershell reporting security

Last synced: 10 Apr 2025

https://github.com/teemu-l/execution-trace-viewer

Tool for viewing and analyzing execution traces

pyqt5 python reverse-engineering security security-tools x64dbg

Last synced: 10 May 2025

https://github.com/oisf/suricata-update

The tool for updating your Suricata rules.

ids ips network-monitoring nsm security suricata

Last synced: 15 May 2025

https://github.com/YinWC/Security_Learning

Security Learning For All~

ctf mobile pwn security web

Last synced: 11 Jul 2025

https://github.com/ibm/audit-ci

Audit NPM, Yarn, PNPM, and Bun dependencies in continuous integration environments, preventing integration if vulnerabilities are found at or above a configurable threshold while ignoring allowlisted advisories

audit audit-ci bun ci github-actions npm pnpm security yarn

Last synced: 13 Apr 2025

https://github.com/lazywinadmin/monitor-adgroupmembership

PowerShell script to monitor Active Directory groups and send an email when someone is changing the membership

active-directory hacktoberfest monitoring powershell reporting security

Last synced: 26 Jun 2025

https://github.com/OISF/suricata-update

The tool for updating your Suricata rules.

ids ips network-monitoring nsm security suricata

Last synced: 10 May 2025

https://github.com/saasform/saasform

Add signup & payments to your SaaS in minutes.

authentication payments saas security

Last synced: 15 Mar 2025

https://github.com/pavanw3b/sh00t

Security Testing is not as simple as right click > Scan. It's messy, a tough game. What if you had missed to test just that one thing and had to regret later? Sh00t is a highly customizable, intelligent platform that understands the life of bug hunters and emphasizes on manual security testing.

django penetration-testing python security

Last synced: 02 Apr 2025

https://github.com/Scille/parsec-cloud

Open source Dropbox-like file sharing with full client encryption !

cloud dropbox file-sharing privacy security sharing-data

Last synced: 14 Mar 2025

https://github.com/paradigmxyz/evmbench

A benchmark and harness for finding and exploiting smart contract bugs

agents ai audit blockchain blockchain-technology eth ethereum evm security solidity testing ui

Last synced: 24 Feb 2026

https://github.com/laxa/HackingTools

Exhaustive list of hacking tools

list security

Last synced: 19 Jul 2025

https://github.com/edoverflow/contact.sh

An OSINT tool to find contacts in order to report security vulnerabilities.

bugbounty infosec osint security

Last synced: 06 Apr 2025

https://github.com/lucasfaudman/apkscan

Scan for secrets, endpoints, and other sensitive data after decompiling and deobfuscating Android files. (.apk, .xapk, .dex, .jar, .class, .smali, .zip, .aar, .arsc, .aab, .jadx.kts).

android apktool cfr concurrency decompiler decompiler-java enjarify fernflower jadx java krakatau mobile penetration-testing procyon secret-scanner secret-scanning security security-tools

Last synced: 05 Apr 2025

https://github.com/Laxa/HackingTools

Exhaustive list of hacking tools

list security

Last synced: 03 Apr 2025

https://github.com/R3LI4NT/Wifi-Hack

Herramienta automatizada para crackear redes WiFi con protección WPA2 y WPS.

aircrack hacking-tool linux python3 security wifi-hack wifi-hacking wifihack wpa2 wps

Last synced: 18 Jul 2025

https://github.com/etherdream/js-port-knocking

Web 端口敲门的奇思妙想

ddos-mitigation javascript portknocking security

Last synced: 08 May 2025

https://github.com/IBM/audit-ci

Audit NPM, Yarn, PNPM, and Bun dependencies in continuous integration environments, preventing integration if vulnerabilities are found at or above a configurable threshold while ignoring allowlisted advisories

audit audit-ci bun ci github-actions npm pnpm security yarn

Last synced: 25 Mar 2025

https://github.com/atexio/mercure

Mercure is a tool for security managers who want to train their colleague to phishing.

campaign email hacking phishing python security

Last synced: 02 Apr 2025

https://github.com/synwall/synwall

A zero-configuration (IoT) firewall

c driver firewall linux-kernel security

Last synced: 09 Apr 2025

https://github.com/EdOverflow/contact.sh

An OSINT tool to find contacts in order to report security vulnerabilities.

bugbounty infosec osint security

Last synced: 12 Jul 2025

https://github.com/mrwiora/nameinator

NAMEinator DNS Benchmark tool (namebench successor)

dns go security

Last synced: 14 Jan 2026

https://github.com/kosty-cloud/kosty

Identify AWS cost waste and security vulnerabilities across 16 core services with a single command

aws cloud cost finops security

Last synced: 26 Apr 2026

https://github.com/googlecloudplatform/jit-groups

JIT Groups is an open source application that lets you implement secure, self-service access management for Google Cloud using groups.

gcp google-cloud iam privileged-access-management security

Last synced: 16 May 2025

https://github.com/tinyclub/elinux

嵌入式 Linux 知识库 (elinux.org) 中文翻译计划;本项目发起人发布了《360° 剖析 Linux ELF》视频课程,欢迎订阅:https://www.cctalk.com/m/group/88089283

android boards bootloader chinese-translation debugging drivers embedded-linux fastboot firmware hardware linux multimedia network profiling realtime security toolchain tracing

Last synced: 09 Apr 2025

https://github.com/zeek/spicy

C++ parser generator for dissecting protocols & files.

parsing security spicy zeek

Last synced: 13 Jun 2025

https://github.com/enygma/expose

An Intrusion Detection System library loosely based on PHP IDS

intrusion-detection php phpids security

Last synced: 08 Oct 2025

https://github.com/destiner/blocksmith

Bitcoin/Ethereum key manipulation

bitcoin cryptocurrency cryptography ethereum security

Last synced: 20 Oct 2025

https://github.com/bolunwang/backdoor

Code implementation of the paper "Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks", at IEEE Security and Privacy 2019.

backdoor-attacks deep-learning keras python security trojan

Last synced: 27 Jul 2025

https://github.com/gremwell/o365enum

Enumerate valid usernames from Office 365 using ActiveSync, Autodiscover v1, or office.com login page.

office365 security user-enumeration

Last synced: 07 Apr 2025

https://github.com/securityfirst/Umbrella_android

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with a kidnap. Umbrella has best practice guides in over 40 topics in multiple languages. Used daily by people working in high risk countries - journalists, activists, diplomats, business travelers etc.

activism advice crypto encryption hacking human-rights-defenders infosec journalism lessons opensource protest risk security snowden travel umbrella

Last synced: 11 Jul 2025

https://github.com/HugoRCD/shelve

Open-source secret & environment management. Secure, simple, collaborative. CLI & Github Sync

cli collaboration developer-experience developer-tools env environment-variables github open-source secrets secrets-management security self-hosted workflow

Last synced: 09 Jul 2025

https://github.com/mrexodia/perfect-dll-proxy

Perfect DLL Proxying using forwards with absolute paths.

dll-hijacking redteam-tools reverse-engineering security windows

Last synced: 13 Apr 2025

https://github.com/YingtongDou/CARE-GNN

Code for CIKM 2020 paper Enhancing Graph Neural Network-based Fraud Detectors against Camouflaged Fraudsters

datamining deep-learning fraud-detection fraud-prevention graphneuralnetwork machine-learning reinforcement-learning security

Last synced: 11 May 2025

https://github.com/albuch/sbt-dependency-check

SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). :rainbow:

appsec cve devops devsecops infosec nvd owasp owasp-dependencycheck sbt sbt-plugin scala security security-audit security-automation software-composition-analysis software-security static-analysis vulnerabilities vulnerability-scanners

Last synced: 12 Jan 2026

https://github.com/trailofbits/osquery-extensions

osquery extensions by Trail of Bits

intrusion-detection monitoring osquery security sql

Last synced: 27 Oct 2025

https://github.com/jakiboy/revens

Windows-based AI-powered Reverse Engineering Toolkit "AIO", Built for Security (Malware analysis, Pentesting) & Educational purposes.

awesome-list awesome-lists malware-analysis penetration-testing reverse-engineering security

Last synced: 02 Apr 2026

https://github.com/yingtongdou/care-gnn

Code for CIKM 2020 paper Enhancing Graph Neural Network-based Fraud Detectors against Camouflaged Fraudsters

datamining deep-learning fraud-detection fraud-prevention graphneuralnetwork machine-learning reinforcement-learning security

Last synced: 09 Apr 2025

https://github.com/deadbits/InsecureProgramming

mirror of gera's insecure programming examples | http://community.coresecurity.com/~gera/InsecureProgramming/

c exploitation learning-exercise security security-vulnerability vulnerabilities

Last synced: 20 Mar 2025

https://github.com/0x4D31/salt-scanner

Linux vulnerability scanner based on Salt Open and Vulners audit API, with Slack notifications and JIRA integration

devops devops-tools python salt saltstack security security-audit security-scanner security-tools vulnerability-scanners vulnerability-scanning

Last synced: 22 Mar 2025

https://github.com/bridgecrewio/checkov-action

This GitHub Action runs Checkov against infrastructure-as-code, open source packages, container images, and CI/CD configurations to identify misconfigurations, vulnerabilities, and license compliance issues.

bridgecrew compliance devsecops hacktoberfest marketplace scanning security static-analysis terraform

Last synced: 14 May 2025

https://github.com/baidu-security/app-env-docker

基于 Docker 的真实应用测试环境

docker openrasp security

Last synced: 12 Jan 2026

https://github.com/0x4d31/salt-scanner

Linux vulnerability scanner based on Salt Open and Vulners audit API, with Slack notifications and JIRA integration

devops devops-tools python salt saltstack security security-audit security-scanner security-tools vulnerability-scanners vulnerability-scanning

Last synced: 01 Oct 2025

https://github.com/autistic-symposium/blockchains-security-toolkit

👾 notes and resources on decentralized protocols (e.g. oracles, bridges, honeypots, cryptography, decompilers, static analysis, bug bounties)

aurora blockchain blockchain-security cypherpunk defi ethereum evm near rust security smart-contracts solidity

Last synced: 28 Feb 2025

https://github.com/aboutcode-org/aboutcode

AboutCode project: tools and data to uncover things about code: the provenance, origin, license, and more (packages, security, quality, etc.) of FOSS code. Get started at https://aboutcode.readthedocs.io/

aboutcode dejacode license purl sbom sca scancode security

Last synced: 28 Jan 2026

https://github.com/the-osint-toolbox/website-osint

You will find a wealth of resources to help with your Website investigations.

analytics archive archives dns domain favicon hosting ip osint security url website whois

Last synced: 15 Feb 2026

https://github.com/SPuerBRead/shovel

Docker容器逃逸工具(Docker Escape Tools)

capability container docker escape security security-tools

Last synced: 04 Apr 2025

https://github.com/panagiks/rspet

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation scenario.

backdoor hacking pentesting plug-ins post-exploitation reverse-shell security security-audit udp-flood udp-spoof

Last synced: 06 Apr 2025

https://github.com/mrwiora/NAMEinator

NAMEinator DNS Benchmark tool (namebench successor)

dns go security

Last synced: 21 Mar 2025

https://github.com/PeterMosmans/security-scripts

A collection of security related Python and Bash shell scripts. Analyze hosts on generic security vulnerabilities. Wrapper around popular tools like nmap (portscanner), nikto (webscanner) and testssl.sh (SSL/TLS scanner)

nikto nmap python security security-scanner security-tools ssl testssl

Last synced: 08 Apr 2025

https://github.com/lukehinds/nono

A secure, kernel-enforced capability sandbox for AI agents

ai ai-agents isolation sandbox security

Last synced: 10 Feb 2026

https://github.com/opencybersecurityalliance/stix-shifter

This project consists of an open source library allowing software to connect to data repositories using STIX Patterning, and return results as STIX Observations.

cybersecurity hacktoberfest ocsf python security security-automation security-tools stix stix2 threat threat-hunting threat-intelligence threatintel

Last synced: 27 Feb 2026

https://github.com/cisagov/scubagoggles

SCuBA Secure Configuration Baselines and assessment tool for Google Workspace

cisa cybersecurity google google-workspace gws opa open-policy-agent open-source python scuba scubaconnect security security-automation

Last synced: 14 Oct 2025

https://github.com/Idov31/MrKaplan

MrKaplan is a tool aimed to help red teamers to stay hidden by clearing evidence of execution.

attack cyber cybersecurity evasion infosec infosectools powershell red-team red-teaming security security-tools windows

Last synced: 21 Jul 2025

https://github.com/wolfssl/wolfssl-examples

Example applications using the wolfSSL lightweight SSL/TLS library

cms cryptography dtls embedded examples freertos iot pkcs7 psa psk security signature-verification ssl tls tpm2 x509

Last synced: 15 May 2025

https://github.com/panagiks/RSPET

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation scenario.

backdoor hacking pentesting plug-ins post-exploitation reverse-shell security security-audit udp-flood udp-spoof

Last synced: 15 May 2025

https://github.com/voltcyclone/pcileechfwgenerator

Automatically generates custom pcileech firmware locally from real pcie devices

dma pcie pcileech pcileech-fpga pcileech-stealth security

Last synced: 30 May 2026

https://github.com/DegateCommunity/Degate

A modern and open-source cross-platform software for chips reverse engineering.

chips cpp cross-platform cybersecurity gui multi-platform reverse-engineering security security-tools verilog vhdl vlsi

Last synced: 12 May 2025

https://github.com/sigstore/sigstore-python

A Sigstore client written in Python

codesigning python security supply-chain

Last synced: 26 Jan 2026

https://github.com/idov31/mrkaplan

MrKaplan is a tool aimed to help red teamers to stay hidden by clearing evidence of execution.

attack cyber cybersecurity evasion infosec infosectools powershell red-team red-teaming security security-tools windows

Last synced: 09 Apr 2025

https://github.com/Esser50K/EvilTwinFramework

A framework for pentesters that facilitates evil twin attacks as well as exploiting other wifi vulnerabilities

evil-twin framework hacking pentesters security toolkit

Last synced: 02 Apr 2025

https://github.com/esser50k/eviltwinframework

A framework for pentesters that facilitates evil twin attacks as well as exploiting other wifi vulnerabilities

evil-twin framework hacking pentesters security toolkit

Last synced: 06 Apr 2025

https://github.com/automorphic-ai/aegis

Self-hardening firewall for large language models

adversarial-attacks large-language-models llmops prompt-injection security

Last synced: 28 Mar 2025

https://github.com/cuprate/cuprate

Cuprate, an upcoming experimental, modern & secure Monero node. Written in Rust

cryptocurrency monero monero-integrations monerod network network-programming peer-to-peer rust rust-lang security

Last synced: 23 Oct 2025

https://github.com/passbolt/passbolt_browser_extension

Browser extensions (Firefox, Edge & Chrome) for Passbolt the open source password manager for teams

browser-extension manager passbolt password password-manager productivity security

Last synced: 21 Jan 2026

https://github.com/r3li4nt/wifi-hack

Herramienta automatizada para crackear redes WiFi con protección WPA2 y WPS.

aircrack hacking-tool linux python3 security wifi-hack wifi-hacking wifihack wpa2 wps

Last synced: 01 May 2026

https://github.com/adgaultier/tamanoir

An eBPF🐝 Keylogger with C2-based RCE payload delivery

aya ebpf hacking keylogger linux ratatui rust security tonic

Last synced: 04 Apr 2025

https://github.com/common-fate/iamzero

Identity & Access Management simplified and secure.

aws cloud cloud-security iam security security-tools

Last synced: 12 Jan 2026

https://github.com/phellipeandrade/rbac

Hierarchical Role-Based Access Control for Node.js

acl authorization hierarchical javascript nodejs permissions rbac role security

Last synced: 30 Mar 2025