An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/0xthiebaut/sigmai

Import specific data sources into the Sigma generic and open signature format.

ids logging misp monitoring security siem sigma signatures

Last synced: 10 Oct 2025

https://github.com/smx-smx/asmtool

Firmware dumper and various utilities for ASMedia USB Controllers and related firmware

asmedia firmware firmware-tools linux security usb usb-controller

Last synced: 24 Oct 2025

https://github.com/minibolt-guide/minibolt

A step-by-step guide to building a Bitcoin & Lightning node, and other stuff on a personal computer

bitcoin bitcoin-wallet cryptocurrency cryptography diy electrum guide lightning lightning-network nostr p2p security self-hosted server web

Last synced: 05 Apr 2025

https://github.com/Hultner/safemd

Safety first markdown rendering

markdown md python python3 render rendering security

Last synced: 19 Jul 2025

https://github.com/kakwa/uts-server

Micro RFC 3161 Time-Stamp server written in C.

c civetweb cryptography openssl rfc-3161 security time-stamp

Last synced: 26 Jul 2025

https://github.com/odensc/janus

Python script to create an Android APK exploiting the Janus vulnerability.

android janus security

Last synced: 05 May 2025

https://github.com/jedisct1/etchdns

A new DNS proxy designed for simplicity, security and extensibility with WebAssembly plugins.

cache dns edgedns extism proxy security wasm webassembly

Last synced: 01 May 2026

https://github.com/jaybrown/dnscrypt-menu

Manage DNSCrypt from the macOS menu bar (BitBar plugin)

bash bitbar dns dnscrypt macos network osx privacy protection script security shellscript

Last synced: 06 Mar 2026

https://github.com/607011/qt-sesam

c't SESAM Password Manager (Qt version)

cplusplus linux macos password-manager qt security sesam windows

Last synced: 12 Apr 2025

https://github.com/elastic/silhouette

Keep it secret, keep it safe

security windows

Last synced: 09 Apr 2025

https://github.com/nccgroup/s3_objects_check

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

aws s3 security

Last synced: 26 Apr 2025

https://github.com/gnothiseautonlw/burp-shell-fwd-lfi

A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration

burp-extensions burp-plugin burpsuite burpsuite-extender penetration-testing penetration-testing-tools pentesting security security-tools

Last synced: 11 Jul 2025

https://github.com/devexpress-examples/xaf_security_e4908

This repository contains examples for .NET Role-based Access Control, Permission Management, and OData / Web / REST API Services for Entity Framework and XPO ORM

asp-net-core asp-net-core-mvc aspnet aspnetcore authentication authentication-middleware authorization blazor dotnet dotnet-core entityframework entityframeworkcore netcore orm row-level-security security webapi winforms xaf xpo

Last synced: 04 Apr 2025

https://github.com/ryuchen/panda-sandbox

这是一个基于 Cuckoo 开源版本的沙箱的修订版本, 该版本完全为了适配国内软件环境所打造

cuckoo cuckoo-sandbox malware malware-analysis sandbox security

Last synced: 21 Mar 2025

https://github.com/frankmorgner/opensctoken

Use OpenSC in macOS CryptoTokenKit.

macos opensc security smartcard

Last synced: 14 Apr 2025

https://github.com/oxsecurity/codetotal

Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.

code-quality-analyzer iac megalinter sast sbom sbom-generator secrets-detection security supply-chain supply-chain-security vulnerability-scanners

Last synced: 06 Aug 2025

https://github.com/lunal-dev/home

Lunal is the AI confidential compute platform. We run your AI workloads (inference, training, agents) inside hardware-encrypted environments called Trusted Execution Environments (TEEs). Your data and code stay private while being processed. Your code can't be tampered with. You can cryptographically verify both claims without trusting us.

confidential-computing cryptography privacy security tee trusted trusted-computing verifiability zero-knowledge

Last synced: 04 Apr 2026

https://github.com/adrianlois/dfir-detection-engineering

Digital Forensics Incident Response and Detection engineering: Análisis forense de artefactos comunes y no tan comunes. Técnicas anti-forense y detección de técnicas utilizadas por actores maliciosos para la evasión de sistemas de protección y monitorización.

anti-forense artefactos artefacts cybersecurity deteccion detection-engineering dfir digital-forensics evidencias forense forensics incident-response linux macosx malware security tips tricks windows

Last synced: 09 Apr 2025

https://github.com/enygma/yubikey

PHP library to interface with the Yubikey REST API

php security token yubikey

Last synced: 04 Apr 2025

https://github.com/sorah/itamae-secrets

Encrypted Data Bag for Itamae

infrastructure-as-code itamae security

Last synced: 17 Sep 2025

https://github.com/garagon/aguara

Security scanner for AI agent skills and MCP servers. Static analysis, incident response, no LLM. One binary. Detection engine behind oktsec.

ai-agents ai-security claude data-exfiltration devsecops golang mcp mcp-server model-context-protocol prompt-injection sast security security-scanner static-analysis supply-chain-security

Last synced: 17 May 2026

https://github.com/confluentinc/cp-demo

Confluent Platform Demo including Apache Kafka, ksqlDB, Control Center, Schema Registry, Security, Schema Linking, and Cluster Linking

confluent confluent-platform connect demo kafka ksql ksqldb sasl security ssl

Last synced: 24 Jun 2026

https://github.com/apache/casbin-aspnetcore

Casbin.NET integration middleware and sample code for ASP.NET Core

abac acl aspnet aspnetcore auth authorization casbin dotnet rbac security

Last synced: 09 May 2026

https://github.com/wookey-project/ewok-kernel

A secure and high performances microkernel for building secure MCU-based IoTs

ada arm armv7m embedded ewok ewok-kernel microcontroller microcontroller-firmware microkernel security spark

Last synced: 03 Sep 2025

https://github.com/dduzgun-security/github-self-hosted-runners

Guideline of best practices to follow to configure Github Enterprise Cloud self-hosted runners in a secure way.

github-actions runner security

Last synced: 12 Apr 2025

https://github.com/sap/risk-explorer-for-software-supply-chains

A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and other resources. The taxonomy as well as related safeguards can be explored using an interactive visualization tool.

open-source security

Last synced: 06 Apr 2025

https://github.com/hyperoslo/Keychains

:key: A keychain wrapper that is so easy to use that your cat could use it.

access-group account keychain password security service

Last synced: 02 Aug 2025

https://github.com/secutils-dev/secutils

Secutils.dev is an open-source, versatile, yet simple security toolbox for engineers and researchers

api certificate-authority certificates cyber-threat-intelligence developer-tools dsa ec open-security pem pkcs12 pkcs8 rsa-cryptography rust security security-tools x509

Last synced: 27 Sep 2025

https://github.com/steccas/ProtonClient

An unofficial desktop client for ProtonMail done with electron nativefier

bridge client electron electron-plugins email encryption linux mac mail multiplatform nativefier privacy proton protonmail security swiss windows

Last synced: 27 Mar 2025

https://github.com/stoplightio/spectral-owasp-ruleset

Improve the security of your API by detecting common vulnerabilities as defined by OWASP and enforced with Spectral.

api hacktoberfest openapi openapi3 openapi31 security

Last synced: 12 Apr 2025

https://github.com/shuffle/openapi-apps

Swagger/ OpenAPI specifications for security products and services

api apis cyber cybersecurity openapi openapi-specifications security security-industry shuffle swagger

Last synced: 04 Apr 2025

https://github.com/peterdavehello/chkdomain

🔍 Discover if a domain is resolvable or blocked by secure DNS and Ad-blocking services, and experience the innovative idea of DaaS - DNS as an Intelligence Service.

adblock cybersecurity dns domain filter hacktoberfest infosec malware osint phishing security threat-intelligence

Last synced: 12 Jul 2025

https://github.com/hyperoslo/keychains

:key: A keychain wrapper that is so easy to use that your cat could use it.

access-group account keychain password security service

Last synced: 22 Apr 2025

https://github.com/xairy/unlockdown

Disabling kernel lockdown on Ubuntu without physical access

exploit linux-kernel lockdown secure-boot security

Last synced: 02 Apr 2026

https://github.com/dajiaji/hpke-js

A Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API.

aead cryptography encryption hpke kdf kem kyber ml-kem post-quantum pqc rfc9180 security webcrypto x-wing

Last synced: 01 Mar 2026

https://github.com/bongochong/CWP-Utilities

Combined Windows Privacy Utilities | Hosts file updater, block list manager, and more. Open source tools for Windows users, to help ensure privacy & security. Block ads, spyware domains, and other malicious activity/traffic, all through a simple interface.

ad-blocking ancient-truths automation bash batch bittorrent blocklists foss freedom gnu hosts hostsman javascript linux p2p portable privacy scripting security windows

Last synced: 29 Apr 2025

https://github.com/WeebDataHoarder/go-away

[Mirror] Self-hosted abuse detection and rule enforcement against low-effort mass AI scraping and bots.

ai-scraping http-proxy mirror security

Last synced: 06 Feb 2026

https://github.com/chocapikk/cve-2023-6553

Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution

cve cve-2023-6553 cybersecurity exploit hacking infosec php python rce security security-research vulnerability wordpress

Last synced: 19 Apr 2025

https://github.com/cyberark/agentwatch

A powerful AI observability framework that provides comprehensive insights into agent interactions across platforms, enabling developers to monitor, analyze, and optimize AI-driven applications with minimal integration effort.

agent agentic agentic-ai ai cybersecurity large-language-models llm llm-framework llm-observability llm-tools machine-learning monitoring observability security

Last synced: 22 Jul 2025

https://github.com/netflix-skunkworks/cloudaux

Cloud Auxiliary is a python wrapper and orchestration module for interacting with cloud providers

security

Last synced: 07 Apr 2025

https://github.com/bongochong/cwp-utilities

Combined Windows Privacy Utilities | Hosts file updater, block list manager, and more. Open source tools for Windows users, to help ensure privacy & security. Block ads, spyware domains, and other malicious activity/traffic, all through a simple interface.

ad-blocking ancient-truths automation bash batch bittorrent blocklists foss freedom gnu hosts hostsman javascript linux p2p portable privacy scripting security windows

Last synced: 20 Jul 2025

https://github.com/defectdojo/sample-scan-files

Sample scan files for testing DefectDojo imports

appsec scans security

Last synced: 26 Jan 2026

https://github.com/frankmorgner/OpenSCToken

Use OpenSC in macOS CryptoTokenKit.

macos opensc security smartcard

Last synced: 22 Apr 2025

https://github.com/mofneko/emulatordetector

Android Emulator Detector Unity Compatible.

android-library emulator security unity3d-plugin

Last synced: 12 Apr 2025

https://github.com/dtaniwaki/rack-secure-upload

Upload files securely

rack rails security upload

Last synced: 11 Nov 2025

https://github.com/owenrumney/go-sarif

Go library for SARIF - Static Analysis Results Interchange Format

hacktoberfest reporting-tools sarif sarif-report security security-tools static-analysis tfsec

Last synced: 15 May 2025

https://github.com/mrrazvi/blockchain-development

A complimentary course for an understanding of blockchain and its development like custom blockchain, dapps, etc.

bitcoin blockchain course cryptography dapps ethereum roadmap security smart-contracts

Last synced: 07 May 2025

https://github.com/garywill/lan-port-scan-forbidder

Forbid untrusted webs to access localhost or LAN. An anti-scan protection 🛡️🏡

browser browser-extension firefox firefox-addon firefox-extension lan-port-scanner privacy security webextension

Last synced: 05 Mar 2026

https://github.com/chocapikk/cve-2023-4966

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

citrix cve-2023-4966 exploit exploitation infosec memory-leak netscaler network-security open-source pentesting python security security-research session-tokens vulnerability

Last synced: 19 Apr 2025

https://github.com/BugHunterID/BugHunterID

Para pencari bug / celah kemanan bisa bergabung.

bounty bug bugbounty bughunterid hackerone indonesia security

Last synced: 10 Mar 2025

https://github.com/fergarrui/custom-bytecode-analyzer

Java bytecode analyzer customizable via JSON rules

analysis analyzer bughunting bytecode callgraph java json security static-analysis

Last synced: 26 Aug 2025

https://github.com/quicsec/quicsec

HTTP/3-enable existing HTTP apps. Leverage HTTP3 native features and auto-enable workload identity (SPIFFE), AuthN (mTLS/x509, OIDC/Auth0-Okta), AuthZ (OPA), defense-in-depth (WAAP/WAF), and observability (metrics, logs, alerting, dashboard).

auth0 authentication cert-manager cloud-native grafana http http3 kubernetes loki metrics mtls oidc okta open-policy-agent prometheus quic security spiffe waf zero-trust

Last synced: 12 Apr 2025

https://github.com/caverav/auditforge

AuditForge is a pentest reporting application making it simple and easy to write your findings and generate a customizable report.

audit cybersecurity infosec penetration-testing pentesting pentesting-tools reporting reporting-tool security security-tools vulnerabilities

Last synced: 20 Jan 2026

https://github.com/netinvent/windows_tools

Collection of various interfaces for Windows functionality in a Pythonic way

code-signing firewall ntfs security windows

Last synced: 04 Apr 2025

https://github.com/rix4uni/scope

An automated GitHub Actions-based crawler that fetches and updates public scopes from popular bug bounty platforms (like Hackerone/Bugcrowd/Intigriti/etc) (updates every 10 minutes)

bug-bounty bugbounty bugbountytips bugcrowd hackenproof hackerone hacking infosec intigriti osint osint-tool penetration-testing pentest-tool pentesting recon reconnaissance security security-tools vrp yeswehack

Last synced: 06 Mar 2026

https://github.com/rtrlib/rtrlib

An open-source C implementation of the RPKI/Router Protocol client

bgp c routing rpki rtr rtr-client rtr-server rtrlib security

Last synced: 11 Apr 2025

https://github.com/jfrog/jfrog-docker-desktop-extension

🐸 Scans any of your local Docker images for security vulnerabilities. 🐋

artifactory docker docker-extension hacktoberfest jfrog security security-audit security-tools vulnerabilities xray

Last synced: 10 Oct 2025

https://github.com/enquo/pg_enquo

Postgres extension to allow encrypted query operations

cryptography encryption enquo hacktoberfest postgresql rust security

Last synced: 27 Feb 2025

https://github.com/infamousjoeg/cybr-cli

A "Swiss Army Knife" command-line interface (CLI) for easy human and non-human interaction with @CyberArk suite of products.

cli client-library command-line command-line-interface command-line-tool conjur cyberark cyberark-identity cyberark-pas go golang iam identity-security pas-api privileged-access-security security

Last synced: 07 Apr 2025

https://github.com/pypa/gh-action-pip-audit

A GitHub Action for pip-audit

github-actions pip security supply-chain

Last synced: 05 Apr 2025

https://github.com/umutcamliyurt/mocktraffic

A random DNS, HTTPS internet traffic noise generator for Android

dns https opsec privacy security traffic-generator traffic-inspection

Last synced: 10 Apr 2025

https://github.com/IC3Hydra/Hydra

Framework for cryptoeconomic contract security, decentralized security bounties. Live on Ethereum.

bounties ethereum security smartcontracts

Last synced: 15 Mar 2025

https://github.com/codingo/ransomware-json-dataset

Compiles a json dataset using public sources that contains properties to aid in the detection and mitigation of over 1000 variants of ransomware.

dataset-generation detection excel-to-json json json-dataset mitigation prevention ransomware ransomware-prevention ransomware-resources ransomware-summary security security-audit security-hardening security-vulnerability spreadsheet wannacry

Last synced: 16 Apr 2025

https://github.com/drew-alleman/dystopia

Low to medium multithreaded Ubuntu Core honeypot coded in Python.

honeypot multithreading python security socket ssh telnet ubuntu

Last synced: 13 Jul 2025

https://github.com/wiz-sec-public/namespacehound

NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.

containers k8s kubernetes multi-tenancy security

Last synced: 03 Apr 2026

https://github.com/pyupio/pyup-django

Displays a red warning banner if you are running an insecure Django release.

django security

Last synced: 21 Aug 2025

https://github.com/matiasinsaurralde/evilredis

Script for doing evil stuff to Redis servers (for educational purposes only).

pentesting redis security

Last synced: 22 Mar 2025

https://github.com/rogeriozambon/http-protection

This library protects against typical web attacks. It was inspired in rack-protection Ruby gem.

crystal http middlewares security

Last synced: 27 Mar 2025

https://github.com/GoogleCloudPlatform/gke-vault-demo

This demo builds two GKE Clusters and guides you through using secrets in Vault, using Kubernetes authentication from within a pod to login to Vault, and fetching short-lived Google Service Account credentials on-demand from Vault within a pod.

containers gcp gke gke-helmsman hashicorp-vault kubernetes kubernetes-engine security vault

Last synced: 02 Apr 2025

https://github.com/antoinet/swiss-bugbounty-programs

List of bug bounty and coordinated vulnerability disclosure programs of companies/organisations in Switzerland

bug-bounty bugbounty security switzerland vulnerability-management

Last synced: 27 Jan 2026

https://github.com/cr4sh/smram_parse

System Management RAM analysis tool

analysis dfir firmware forensics investigation reversing security smm uefi

Last synced: 04 Jul 2025

https://github.com/doyensec/poiex

🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends

collaborative-editing iac security security-tools semgrep vscode vscode-extension

Last synced: 29 Apr 2025

https://github.com/Cr4sh/smram_parse

System Management RAM analysis tool

analysis dfir firmware forensics investigation reversing security smm uefi

Last synced: 13 Mar 2025

https://github.com/googlecloudplatform/gke-vault-demo

This demo builds two GKE Clusters and guides you through using secrets in Vault, using Kubernetes authentication from within a pod to login to Vault, and fetching short-lived Google Service Account credentials on-demand from Vault within a pod.

containers gcp gke gke-helmsman hashicorp-vault kubernetes kubernetes-engine security vault

Last synced: 14 Apr 2025

https://github.com/kdpisda/django-rls

Row Level Security for Django

django postgres postgresql rls security

Last synced: 08 Apr 2026

https://github.com/shipsecure-labs/eslint-plugin-next

Secure your Next.js applications with @shipsecure/eslint-plugin-next, an ESLint plugin designed to detect and prevent common security vulnerabilities.

eslint eslint-plugin eslint-rules security

Last synced: 05 Apr 2025

https://github.com/enkomio/anathema

.NET instrumentation framework

dotnet hooking instrumentation security security-framework

Last synced: 22 Apr 2025

https://github.com/cycodelabs/cimon-action

Runtime Security Solution for your CI/CD Pipeline

cicd ebpf github-actions hardening linux security security-hardening supply-chain-security

Last synced: 01 Sep 2025

https://github.com/johnsonjason/rvdbg

RVDbg is a debugger/exception handler for Windows processes and has the capability to circumvent anti-debugging techniques. (Cleaner, documented code base being worked on in: core branch)

breakpoint cheat cplusplus cpp debugger exception-handler exceptions exploitation hooks reverse-engineering security windows x86

Last synced: 04 Jul 2025

https://github.com/thalesgroup-cert/suspicious

AI-powered phishing & threat-analysis platform to automatically inspect, classify, and report suspicious emails, files, URLs, IPs, and hashes built for teams and organizations

django django-project docker docker-compose javascript mail mail-analysis python security tool

Last synced: 16 Jan 2026

https://github.com/souk4711/hakoniwa

Process isolation for Linux using namespaces, resource limits, cgroups, landlock and seccomp.

cgroups chroot container landlock linux linux-namespaces process rust sandbox sandboxing seccomp security unshare

Last synced: 16 May 2026

https://github.com/ergo/ziggurat_foundations

Framework agnostic set of sqlalchemy classes that make building applications that require permissions an easy task.

authentication authorization flask mixins permission permissions pyramid python security sqlalchemy

Last synced: 25 Jul 2025