An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/visma-prodsec/columbo

Columbo is a computer forensic analysis tool used to simplify and identify specific patterns in compromised datasets.

binary-analysis forensic-analysis forensics security security-tools windows

Last synced: 10 Mar 2026

https://github.com/bouke/srp

Secure Remote Password (SRP) for Swift

authentication encryption password rfc-2945 rfc-5054 security srp srp-6a swift

Last synced: 24 Jul 2025

https://github.com/yunwei37/eunomia

A lightweight eBPF-based Monitor tool:run ebpf as a service!

cloud-native container cpp cpp-library cpp20 ebpf kubernetes monitor observability prometheus security

Last synced: 07 Aug 2025

https://github.com/valpackett/freshcerts

ACME certificate protocol (Let's Encrypt) proxy client with a dashboard and monitoring

acme certificate dashboard letsencrypt monitoring security ssl tls

Last synced: 18 Aug 2025

https://github.com/rix4uni/medium-writeups

This repository updates latest Bug Bounty medium writeups every 10 minutes, https://readmedium.com/Medium_URL, https://archive.ph/Medium_URL, https://freedium.cfd/Medium_URL

bug-bounty bugbounty bugbountytips hacking infosec osint osint-resources osint-tool penetration-testing pentest-tool pentesting recon reconnaissance reconnaissance-bugbounty-writeups security security-tools threat-intelligence

Last synced: 15 Apr 2025

https://github.com/grapheneos/platform_build

Make Build System (being phased out upstream)

android grapheneos privacy security

Last synced: 04 Apr 2025

https://github.com/chaitin/mimicry

Mimicry is a dynamic deception tool that actively deceives an attacker during exploitation and post-exploitation.

backdoor blue-team brute-force deception honeypot incident-response security security-tools waf webshell

Last synced: 28 Feb 2026

https://github.com/libtea/frameworks

Microarchitectural attack development frameworks for prototyping attacks in native code (C, C++, ASM) and in the browser

aarch64 assembly c cache-attack meltdown microarchitecture ppc64 research security sgx side-channel-attacks spectre x86

Last synced: 20 Apr 2025

https://github.com/cr4sh/qc_debug_monitor

Debug messages monitor for Qualcomm cellular modems

baseband celluar debugging firmware lte qualcomm reverse-engineering security wireless

Last synced: 07 Oct 2025

https://github.com/PalindromeLabs/Java-Deserialization-CVEs

Compiled dataset of Java deserialization CVEs

cve deserialization java-deserialization security

Last synced: 11 Jul 2025

https://github.com/cyllective/oauth-labs

oauth-labs: an intentionally vulnerable set of OAuth 2.0 labs for security training and learning

appsec ctf hacking oauth2 pentesting security vulnapp vulnerable

Last synced: 02 Apr 2025

https://github.com/alienrobotarmy/ctunnel

ctunnel is a proxy and VPN software for tunneling TCP and UDP connections securely

c gnutls openssl privacy proxy security tunnel-client tunnel-server tunneling tuntap vpn vpn-client vpn-server

Last synced: 02 Apr 2025

https://github.com/jaybrown/macos-security-updates

Notifies the user when macOS Security components like Gatekeeper and XProtect have been updated

catalina efi gatekeeper ibridge launchagent macos malware mrt privacy protection security tcc xplorer xprotect

Last synced: 09 Jul 2025

https://github.com/brosck/Pingoor

「🚪」Linux Backdoor based on ICMP protocol

backdoor c hacking icmp linux persistence protocol security

Last synced: 11 Jul 2025

https://github.com/ciphermarco/BOAST

The BOAST Outpost for AppSec Testing: a server designed to receive and report Out-of-Band Application Security Testing (OAST) reactions.

appsec appsec-testing go golang security security-testing security-tools

Last synced: 10 May 2025

https://github.com/secrethub/secrethub-go

Golang SDK for the SecretHub Secrets Management API

devops go golang hacktoberfest secrets secrets-management security

Last synced: 09 Jul 2025

https://github.com/hahwul/gitls

🖇 Enumerate git repository URL from list of URL / User / Org. Friendly to pipeline

bugbounty butbountytips cli-tool fetcher git github security security-tools tool whitebox-testing

Last synced: 04 Jul 2025

https://github.com/serceman/firewalker

Testing framework for Cloudflare Firewall rules

cloudflare security waf

Last synced: 05 Apr 2025

https://github.com/brosck/pingoor

「🚪」Linux Backdoor based on ICMP protocol

backdoor c hacking icmp linux persistence protocol security

Last synced: 13 Apr 2025

https://github.com/404notf0und/FXY

Security-Scenes-Feature-Engineering-Toolkit, Continuous Integration.一款安全数据特征化工具

data-analysis data-mining feature-engineering machine-learning security security-scenes

Last synced: 11 Jul 2025

https://github.com/syss-research/bluetooth-keyboard-emulator

Simple proof-of-concept software tool for emulating Bluetooth BR/EDR (a.k.a. Bluetooth Classic) keyboards

bluetooth proof-of-concept security security-tools tool

Last synced: 01 Apr 2026

https://github.com/sleeepeer/PoisonedRAG

[USENIX Security 2025] PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

ai machine-learning rag retrieval-augmented-generation security trustworthy-ai

Last synced: 27 Jul 2025

https://github.com/unicistech/unicis-platform-ce

A modern, all-in-one Governance, Risk & Compliance (GRC) solution designed for privacy, security, and compliance teams. As an open-source alternative to Vanta and Drata, this platform empowers teams with full control, flexibility, and transparency—no vendor lock-in, just powerful compliance automation and risk management tailored to your needs.

all-in-one awareness-app compliance-automation compliance-platform cybersecurity cybersecurity-tools governance-risk-compliance grc open-source opensource privacy privacy-tools risk-management security

Last synced: 09 Mar 2026

https://github.com/EdOverflow/smith

Simple wrapper for meg that sieves through meg's output for you.

bugbounty security security-tools

Last synced: 27 Sep 2025

https://github.com/zolagonano/a-ninjas-handbook

A Ninja's Handbook: A book on privacy, security, and anonymity online.

anonymity book guide privacy security

Last synced: 21 Feb 2026

https://github.com/scheb/2fa-bundle

[READ ONLY] A generic interface to implement two-factor authentication in Symfony applications

2fa security symfony symfony-bundle two-factor-authentication

Last synced: 05 Apr 2025

https://github.com/Bouke/SRP

Secure Remote Password (SRP) for Swift

authentication encryption password rfc-2945 rfc-5054 security srp srp-6a swift

Last synced: 23 Jul 2025

https://github.com/sk89q/php-security-checklist

🔐 Comprehensive PHP security checklist predating OWASP (publication, 2009)

owasp php security

Last synced: 25 Jun 2025

https://github.com/cilium/charts

Helm charts repository for the Cilium project

bpf cni helm kubernetes kubernetes-networking security

Last synced: 22 Jul 2025

https://github.com/github/entitlements-config

An example of how Entitlements can be configured

automation entitlements iam security

Last synced: 24 Oct 2025

https://github.com/hectorm/wireguard-setup

WireGuard and Unbound setup with Packer and Terraform / OpenTofu.

hcloud hetzner hetzner-cloud opentofu packer security terraform unbound vpn wireguard

Last synced: 08 May 2025

https://github.com/madhuakula/docker-security-checker

Dockerfile Security Checker using OPA Rego policies with Conftest

conftest docker dockerfile infosec opa opa-rego-policies rego security

Last synced: 12 Oct 2025

https://github.com/sammcj/mcp-package-version

An MCP server that provides LLMs with the latest stable package versions when coding

ai javascript llm mcp node package python security tool typescript versioning versions

Last synced: 09 Apr 2025

https://github.com/williamofai/c-sentinel

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

ai c devops linux llm observability security system-monitoring unix

Last synced: 13 Jan 2026

https://github.com/psecio/propauth

A library for property-based policy evaluation

authorization php policy policy-evaluation property-based-testing security

Last synced: 11 Apr 2025

https://github.com/authcrunch/authcrunch

Authentication Portal based on Caddy Security

auth authentication caddy-security caddy2 security

Last synced: 02 Apr 2026

https://github.com/kguardian-dev/kguardian

A Kubernetes tool leveraging eBPF for advanced Kubernetes security, auto-generating Network Policies, Seccomp Profiles, and more.

ebpf kubernetes security

Last synced: 01 Jun 2026

https://github.com/isfonzar/cryptogo

Protect your sensitive files with a password using this simple and easy file encrypter

encrypter encryption go golang password security

Last synced: 12 May 2025

https://github.com/joychou93/trident

Java通用漏洞修复安全组件

code component java security

Last synced: 16 Jun 2025

https://github.com/valpackett/rusty-sandbox

A sandboxing library for Rust | now on https://codeberg.org/valpackett/rusty-sandbox

capsicum pledge rust sandboxing seatbelt security unix

Last synced: 12 May 2025

https://github.com/cristianzsh/csharp-keylogger

:keyboard: A keylogger written in C# + Send by email

csharp email keylogger malware security security-tools send-email windows

Last synced: 25 Jun 2025

https://github.com/stratosphereips/vellmes-ai-deception-framework

Interactive, dynamic, and realistic LLM honeypots

deception honeypots large-language-models llm security

Last synced: 22 Jan 2026

https://github.com/nozaq/amazon-linux-cis

Bootstrap script for Amazon Linux to comply CIS Amazon Linux Benchmark v2.0.0

amazon-linux aws cis hardening security

Last synced: 16 May 2025

https://github.com/cedricbonhomme/pyhids

A HIDS (host-based intrusion detection system) for verifying the integrity of a system.

bloom-filter hashlookup hids intrusion-detection irc misp python rsa-signature security yara

Last synced: 05 Apr 2025

https://github.com/typo3/phar-stream-wrapper

Interceptors for PHP's native phar:// stream handling in order to enhance security.

deserialization insecure-deserialization phar php security stream-wrapper

Last synced: 15 May 2025

https://github.com/johnsonjason/rudiac

A client-sided anti-cheat developed during a freelance project to "plug-in" to a proprietary client for a private server. Includes memory integrity checks, thread execution restrictions, hook detection, memory honeypots, and more.

anticheat cpp reverse-engineering security windows x86

Last synced: 22 Apr 2026

https://github.com/sensepost/punch-q

👊 A small utility to play with IBM MQ

ibm ibm-mq mq security websphere-mq

Last synced: 16 Apr 2025

https://github.com/404notf0und/fxy

Security-Scenes-Feature-Engineering-Toolkit, Continuous Integration.一款安全数据特征化工具

data-analysis data-mining feature-engineering machine-learning security security-scenes

Last synced: 16 Oct 2025

https://github.com/WuliRuler/SBSCAN

🎭 SBSCAN是一款专注于spring框架的渗透测试工具,可以对指定站点进行springboot未授权扫描/敏感信息扫描以及进行spring框架漏洞扫描与验证的综合利用工具。 [SBSCAN is a penetration testing tool focused on the spring framework that can scan springboot sensitive information/unauthorized for specified sites and scan and validate spring related vulnerabilities]

cve cve-2018-1273 cve-2019-3799 cve-2020-5410 cve-2021-21234 cve-2022-22947 cve-2022-22963 cve-2022-22965 pentest-tool poc scanner security security-tools spring spring-boot spring-vulnerability springboot springboot-vul-scan springframework sprint-vul-scan

Last synced: 07 Sep 2025

https://github.com/jedisct1/wasmsign

A tool to add and verify digital signatures to/from WASM binaries

rust security signatures wasm webassembly

Last synced: 25 Aug 2025

https://github.com/kpcyrd/arch-audit-gtk

Arch Linux Security Update Notifications

arch-audit archlinux security updates

Last synced: 25 Sep 2025

https://github.com/krisnova/hack

Kubernetes security and vulnerability tools and utilities.

exploit hack kubernetes research security tools vector vulnerability

Last synced: 02 Feb 2026

https://github.com/dosx-dev/html-guard

Protect your web-application with Dynamic Style Loading and Real-Time Obfuscation. Easy to use!

application-security css drm easy-to-use framework guard html js module obfuscator protection react reactjs security static vuejs web website

Last synced: 07 May 2025

https://github.com/mohitmishra786/bitsandbytes

A comprehensive systems programming toolkit implementing low-level concepts in C, from memory management to OS internals. Features practical implementations of computer architecture concepts with a focus on performance and hardware interaction.

c-programming computer-architecture concurrency embedded-systems hardware linux low-level low-level-programming memory-management networking operating-systems optimization performance real-time-systems security system-programming unix

Last synced: 11 Jul 2025

https://github.com/aikidosec/firewall-node

Zen protects your Node app against attacks with one line of code. Get peace of mind— at runtime.

attack-defense firewall nodejs nosql-injection path-traversal rasp security shell-injection sql-injection

Last synced: 02 Apr 2026

https://github.com/darxisr/cryline-v5.0

Cryline project - It's a simple test ransomware for Windows OS without stable encryption. Pls use this source code for study purposes only. The author is't responsible for your actions.

assembly bootkit bootloader cipher cplusplus development drive encryption hardware malware mbr notpetya petya programming ransomware security source-code subsystem virus windows

Last synced: 13 Apr 2025

https://github.com/deniskore/llvm

LLVM based obfuscator

llvm llvm-ir nand nor obfuscation obfuscator security

Last synced: 15 Jul 2025

https://github.com/fulls1z3/ngx-auth

Auth0 platform implementation and JWT authentication utility for Angular & Angular Universal

angular angular2 angular4 aot auth auth0 authentication jwt npm-package security server-side-rendering typescript universal

Last synced: 12 Apr 2025

https://github.com/0x4d31/honeyku

A Heroku-based web honeypot that can be used to create and monitor fake HTTP endpoints (i.e. honeytokens).

deception flask heroku honeypot honeytoken infosec python security

Last synced: 12 May 2025

https://github.com/seclab-ucr/saddns

SADDNS: Side Channel Based DNS Cache Poisoning Attack

dns kernel network security side-channel

Last synced: 13 Jul 2025

https://github.com/google/CTAP2-test-tool

Test tool for CTAP2 authenticators

cpp ctap2 fido2 security security-key

Last synced: 11 Jul 2025

https://github.com/lubyruffy/secrss

分析玄武实验室的安全参考来源

security xuanwu

Last synced: 30 Apr 2025

https://github.com/TwiN/g8

⛩️ Go library for protecting your HTTP handlers

authorization bearer go golang hacktoberfest handler library rate-limit rate-limiting security token

Last synced: 08 Apr 2025

https://github.com/thinkalexandria/boringauth

Straightforward password, passphrase, TOTP, and HOTP user authentication

2fa 2factor hotp oath password-store security

Last synced: 09 Jul 2025

https://github.com/prestascan/prestascansecurity

PrestaScan Security is a PrestaShop module allowing you to scan your PrestaShop website to identify malware and known vulnerabilities in PrestaShop core and modules.

cve prestashop prestashop-free-module prestashop-module security security-tools vulnerability-scanners

Last synced: 10 Apr 2025

https://github.com/htrgouvea/nozaki

HTTP fuzzer engine security oriented

api bugbounty fuzzer fuzzing graphql http nozaki perl research rest restfull security

Last synced: 09 Apr 2025

https://github.com/EgeBalci/The-Eye

Simple security surveillance script for linux distributions.

arp-poisoning meterpreter monitoring security spoofing surveillance suspicous-connections

Last synced: 26 Mar 2025

https://github.com/vi/dive

Start programs inside unshare/lxc namespaces easily using UNIX sockets + easy access to capabilities, namespaces, chroot and others.

capabilities chroot linux namespaces prctl security setns

Last synced: 15 Apr 2025

https://github.com/twin/g8

⛩️ Go library for protecting your HTTP handlers

authorization bearer go golang hacktoberfest handler library rate-limit rate-limiting security token

Last synced: 15 Mar 2025

https://github.com/mithril-security/blindbox

BlindBox is a tool to isolate and deploy applications inside Trusted Execution Environments for privacy-by-design apps

ai cloud deployment docker security

Last synced: 12 May 2025

https://github.com/kindspells/astro-shield

Astro integration to enhance your website's security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques.

astro astro-integration content-security-policy hacktoberfest hacktoberfest2024 javascript security subresource-integrity withastro xss-protection

Last synced: 05 Apr 2025

https://github.com/haskell/hackage-security

Hackage security framework based on TUF (The Update Framework)

cabal hackage haskell security tuf

Last synced: 16 May 2025

https://github.com/LubyRuffy/secrss

分析玄武实验室的安全参考来源

security xuanwu

Last synced: 15 May 2025