An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/bgalek/safe-svg

Simple and lightweight library that helps to validate SVG files in security manners.

hacktoberfest security svg xss xss-detection

Last synced: 10 Mar 2026

https://github.com/friendsofredaxo/emailobfuscator

Verschlüsselung von E-Mailadressen zum Schutz vor Spam

email redaxo redaxo-addon security spam

Last synced: 09 Mar 2026

https://github.com/padok-team/git-secret-scanner

Find secrets in git repositories with TruffleHog & Gitleaks

auditing credentials git scan secrets security

Last synced: 07 Apr 2025

https://github.com/dwisiswant0/look4jar

Looking for JAR files that are vulnerable to Log4j RCE (CVE‐2021‐44228)?

golang log4j log4j2 rce security vulnerability

Last synced: 24 Mar 2025

https://github.com/kongbytes/joi-security

Detect security flaws in Joi validation schemas (XSS, SQL injection, ...) 🔥

audits hapi joi js security sql-injection typescript validation web-security xss

Last synced: 25 Dec 2025

https://github.com/banzaicloud/anchore-image-validator

Anchore Image Validator lets you automatically detect or block security issues just before a Kubernetes pod starts.

cloud-native golang kubernetes security

Last synced: 13 Apr 2025

https://github.com/frodox/execute-machine-code-from-memory

Proof of concept example: executing machine code from different memory areas: stack, heap, shared memory

c heap poc security security-testing shm stack

Last synced: 23 Aug 2025

https://github.com/bhvbhushan/vibecop

AI code quality toolkit — deterministic linter for the AI coding era. 22 detectors, GitHub Action PR gate, zero LLM required.

ai ai-code-quality ast ast-grep ci-cd code-quality code-review code-smell developer-tools eslint-alternative github-action javascript linter pull-request python security static-analysis tree-sitter typescript vibe-coding

Last synced: 07 Apr 2026

https://github.com/boitatech/cyber-security-roadmap

O repositório Cyber Security Roadmap é uma iniciativa para ajudar a comunidade de segurança da informação a se orientar sobre o que estudar.

boitatech cyber-security cybersecurity infosec roadmad security

Last synced: 06 Oct 2025

https://github.com/mojtabatajik/sandbox-detection

Contains some tricks to detect Sandboxes and gradually completed

cpp sandbox sandbox-detection security

Last synced: 18 Mar 2025

https://github.com/lmammino/terraform-openvpn

A sample terraform setup for OpenVPN using Let's Encrypt and Certbot to generate certificates

automation example infrastructure network openvpn security terraform tutorial vpn

Last synced: 30 Apr 2025

https://github.com/duaraghav8/solium-plugin-security

The Official Security Plugin for Ethlint (formerly Solium)

ethereum linter security smart-contracts solidity solium soliumplugin

Last synced: 07 May 2025

https://github.com/nullhypothesis/sybilhunter

Hunting for Sybils and anomalies in archived Tor network data.

go security sybil tor tor-network

Last synced: 08 Mar 2026

https://github.com/jeffhacks/smbscan

SMBScan is a tool to enumerate file shares on an internal network.

pentest redteam security security-audit security-tools smb

Last synced: 13 Apr 2025

https://github.com/RootUp/SmuggleShield

Basic protection against HTML smuggling attempts.

blueteam htmlsmuggling purpleteam redteam security

Last synced: 12 Jul 2025

https://github.com/planetis-m/libfuzzer

Thin interface for libFuzzer, an in-process, coverage-guided, evolutionary fuzzing engine.

fuzzing hacking security unit-testing

Last synced: 06 Jul 2025

https://github.com/Saluki/joi-security

Detect security flaws in Joi validation schemas (XSS, SQL injection, ...) 🔥

audits hapi joi js security sql-injection typescript validation web-security xss

Last synced: 05 Mar 2025

https://github.com/timokoessler/easy-waf

An easy-to-use Web Application Firewall (WAF) for Node.js. Can be used with Express, Fastify, NextJS, NuxtJS ... or plain Node.js http.

javascript mit-license nodejs security typescript waf web-application-firewall web-application-security

Last synced: 07 Apr 2025

https://github.com/oke-py/npm-audit-action

GitHub Action to run `npm audit`

github-action npm security vulnerability

Last synced: 28 Jan 2026

https://github.com/deliciousinsights/mongoose-pii

A Mongoose plugin that lets you transparently cipher stored PII and use securely-hashed passwords

bcrypt mongodb mongoose mongoose-plugin password passwords pii pii-ciphering security

Last synced: 27 Oct 2025

https://github.com/rix4uni/xssrecon

XSSRecon automates the process of testing URL parameters for reflection of a test payload rix4uni and further checks how special characters are handled (allowed, blocked, or converted).

bug-bounty bugbounty bugbountytips hacking infosec masshuntxss osint osint-resources osint-tool penetration-testing pentest-tool pentesting recon reconnaissance security security-tools vulnerability xss xss-automation xssrecon

Last synced: 04 Mar 2026

https://github.com/itemir/thundersec

ThunderSec is a security plugin for Mozilla Thunderbird that creates several pieces of additional security functionality, including DNSBL, RBL, SURBL, DKIM and SPF.

dkim dnsbl security spf surbl thunderbird thunderbird-extension

Last synced: 05 Mar 2026

https://github.com/theodo-group/awesome-security-automation

Awesome links to automate your cybersecurity checks

security security-audit security-automation security-tools

Last synced: 02 Feb 2026

https://github.com/telekom-security/tpotmobile

🛜 T-Pot Mobile - The All In One Wireless Honeypot Solution 🍯

deception honeypot mobile raspberrypi security t-pot telekom

Last synced: 28 Oct 2025

https://github.com/oslabs-beta/guardenoql

Simple and customizable security middleware for GraphQL servers in Deno.

deno graphql open-source opine security

Last synced: 30 Apr 2025

https://github.com/echo-devim/litewaf

Lightweight In-App Web Application Firewall for PHP

attack-log attack-prevention php sanity-check security sqlinjection waf xss

Last synced: 06 Sep 2025

https://github.com/ganehag/open-modbusgateway

Modbus over MQTT in a secure manner

modbus mqtt security

Last synced: 17 Jan 2026

https://github.com/jolle/expired-tweets

🐦 Find tweets that contain expired or claimable URLs from your Twitter archive.

cli electron expired-tweets gui nodejs security takeover tweets twitter twitter-archive

Last synced: 05 Mar 2026

https://github.com/mrtc0/kubectf

Kubernetes CTF

ctf kubernetes security

Last synced: 15 Apr 2025

https://github.com/celenityy/Phoenix

Phoenix is a suite of configurations & advanced modifications for Mozilla Firefox, designed to put the user first - with a focus on privacy, security, freedom, & usability.

anti-tracking browser firefox firefox-based firefox-browser gecko hardened hardening mozilla mozilla-firefox privacy private secure security settings speed tracking user-js userjs web-browser

Last synced: 19 Mar 2026

https://github.com/marmelab/ra-in-memory-jwt

Manage React-admin authentication with jwt in memory, not in local storage

jwt react-admin security

Last synced: 24 Oct 2025

https://github.com/andifalk/oidc-workshop-spring-io-2019

Workshop at Spring I/O 2019 on "Securing Microservices with OpenID Connect and Spring Security 5.1"

jwt oauth2 oidc openid-connect security spring-boot spring-security

Last synced: 12 Apr 2025

https://github.com/gui774ume/network-security-probe

A process level network security monitoring and enforcement project for Kubernetes, using eBPF

ebpf enforcement kubernetes linux network-security profile security

Last synced: 29 Jun 2025

https://github.com/benibela/nasty-files

Some files with nasty names

backup-files files lists security security-testing

Last synced: 08 Mar 2026

https://github.com/girste/mcp-cybersec-watchdog

🐕 Cybersecurity monitoring and analysis for Linux servers via MCP

devops linux mcp monitoring python security

Last synced: 30 Jan 2026

https://github.com/yiisoft/security

A set of classes to handle common security-related tasks

decryption encryption hacktoberfest masking password random security signature tampering token yii3

Last synced: 09 Apr 2025

https://github.com/escape-technologies/api-threat-matrix

A comprehensive knowledge base for security professionals to keep track of and build defenses against API attack techniques.

api security threatmatrix threats

Last synced: 04 Aug 2025

https://github.com/step-security/agent

Purpose-built security agent for hosted runners

github-actions security

Last synced: 02 Apr 2026

https://github.com/barseghyanartur/ska

Sign data using symmetric-key algorithm encryption. Validate signed data and identify possible validation errors. Uses sha-(1, 224, 256, 385 and 512)/hmac for signature encryption. Custom hash algorithms are allowed. Useful shortcut functions for signing (and validating) dictionaries and URLs.

data-encryption data-hash django django-rest-framework django-rest-framework-addon encryption password-less-authentication python security

Last synced: 16 Mar 2025

https://github.com/squareboat/security-guidelines

Squareboat's best practices for building highly secure websites and apps.

security

Last synced: 04 Apr 2026

https://github.com/nirdiamant/moltbook-agent-guard

Real-time security for AI agents on Moltbook

ai-agents llm moltbook prompt-injection security

Last synced: 11 Feb 2026

https://github.com/hahwul/ras-fuzzer

RAS(RAndom Subdomain) Fuzzer

bugbounty fuzzer fuzzing hacking security subdomain tools

Last synced: 06 Jul 2025

https://github.com/gavinuhma/checksum.sh

Verify every install script. Checksum.sh is a simple way to download, review, and verify install scripts.

bash checksum install security shell

Last synced: 06 Jul 2025

https://github.com/covert-encryption/covert

An encryption format offering better security, performance and ease of use than PGP. File a bug if you found anything where we are worse than our competition, and we will fix it.

crypto cryptography encryption gpg purb security

Last synced: 27 Mar 2026

https://github.com/jacksongl/npm-vuln-poc

Vulnerabilities discovered in npm packages [Berkeley PL & Security Research]

cve javascript node-js npm proof-of-concept security vulnerabilities

Last synced: 21 Aug 2025

https://github.com/syss-research/slig

Siemens LOGO!8 PLC Password Hacking Proof-of-Concept-Tool

it-security logo8 nmap-scripts security security-vulnerability siemens-logo tool

Last synced: 10 Apr 2025

https://github.com/perry-mitchell/iocane

An odorless, tasteless NodeJS crypto library that dissolves instantly in liquid

crypto-js decryption encoding encryption hmac nodejs pbkdf2 security subtlecrypto web

Last synced: 14 Apr 2025

https://github.com/jackgu1988/dsploit-scripts

Scripts that could be injected in MITM attacks using dSploit

dsploit dsploit-scripts mitm security

Last synced: 09 Jul 2025

https://github.com/hellokoding/hello-sso-jwt-auth

Single Sign On (SSO) Example with JSON Web Token (JWT), Spring Boot

authentication java jwt security spring-boot sso

Last synced: 15 Jun 2025

https://github.com/zitchcode/securehttpclient

Cross-platform HttpClientHandler with TLS1.2 and Certificate Pinning

android c-sharp certificate-pinning dotnet httpclient ios maui security tls xamarin

Last synced: 07 Mar 2026

https://github.com/hectorm/cetusguard

CetusGuard is a tool that protects the Docker daemon socket by filtering calls to its API endpoints.

container daemon docker firewall proxy security

Last synced: 12 Apr 2025

https://github.com/callebtc/electronwall

A tiny firewall for LND that allows or denies channel openings and payment routings.

bitcoin lightning security

Last synced: 16 Dec 2025

https://github.com/risc0/kailua

The Ultimate ZK Proving Software Suite for Securing OP Rollups

dispute-resolution evm kailua optimism rollups security zero-knowledge-proofs

Last synced: 11 Jun 2025

https://github.com/itz-hyperz/firewallgg

A simple program that will search all users in multiple database api's to see if they are banned in any of them. It will return a list of all databases the user is banned in as-well.

application database discord node-module passport security

Last synced: 03 Nov 2025

https://github.com/IQTLabs/Daedalus

Exploring various defensive response options for effectively securing a 5G core-network

5g attack bladerf defense ettus limesdr open5gs sdr security srsran ueransim usrp

Last synced: 28 Mar 2026

https://github.com/fxamacker/webauthn

WebAuthn server library decoupled from http for easy intergration, provides WebAuthn registration and authentication for clients using FIDO2 keys, FIDO U2F keys, TPM, etc.

authentication fido-u2f fido2 go golang passwordless safetynet security u2f webauthn

Last synced: 28 Apr 2025

https://github.com/kubearmor/kubearmor-client

KubeArmor cli tool aka kArmor :robot:

cli kubearmor kubernetes management security tool

Last synced: 04 Apr 2025

https://github.com/raforg/sshdo

controls which commands may be executed via incoming ssh

bsd cli debian freebsd linux macos macosx netbsd openbsd posix redhat security ssh svr4 ubuntu unix

Last synced: 09 Oct 2025

https://github.com/ldsec/drynx

Decentralized, Secure, Verifiable System for Statistical Queries and Machine Learning on Distributed Datasets

data-sharing machine-learning onet privacy-protection security statistical-methods

Last synced: 11 Jan 2026

https://github.com/Contrast-Security-OSS/safelog4j

Safelog4j is an instrumentation-based security tool to help teams discover, verify, and solve log4shell vulnerabilities without scanning or upgrading

iast java log4j log4shell rasp security security-testing vulnerability vulnerability-scanner

Last synced: 11 Jul 2025

https://github.com/johannschopplich/kirby-locked-pages

🔐 Password-protect pages, Panel blueprint included

kirby kirby-plugin password password-lock security

Last synced: 10 Jul 2025

https://github.com/contrast-security-oss/safelog4j

Safelog4j is an instrumentation-based security tool to help teams discover, verify, and solve log4shell vulnerabilities without scanning or upgrading

iast java log4j log4shell rasp security security-testing vulnerability vulnerability-scanner

Last synced: 11 Sep 2025

https://github.com/snyk/serverless-snyk

Serverless plugin for securing your dependencies with Snyk

security serverless snyk vulnerabilities

Last synced: 02 May 2025

https://github.com/tophat-cloud/cumulus

Cumulus is web application weakness monitoring, works with just 3 code lines

javascript security vulnerability weakness weakness-reporting

Last synced: 11 Jul 2025

https://github.com/forderud/runinsandbox

Launch Windows executables & COM servers in a sandboxed or elevated environment.

com security

Last synced: 31 Oct 2025

https://github.com/oliverbebber/az-104-study-notes

Microsoft AZ-104: Azure Administrator Associate Study Notes

azure cloud security

Last synced: 25 Sep 2025

https://github.com/outmansec/SelfIPAdressQuery

一款基于javafx的自有IP地址查询工具(适用于重保、蓝队、攻防演习等场景)

ipchecker java javafx redteam security

Last synced: 07 Sep 2025

https://github.com/brainfucksec/brainfucksec.github.io

My blog about Cybersecurity, Privacy and Systems :)

brainfucksec cyber-security github-pages jekyll-blog privacy security

Last synced: 22 Mar 2025

https://github.com/xward/phoenix_ddos

ddos protection for elixir phoenix project

elixir phoenix plug security

Last synced: 21 Feb 2026

https://github.com/enlightn/laravel-security-checker

Scan your Laravel app dependencies for known security vulnerabilities.

laravel security vulnerability-scanner

Last synced: 26 Oct 2025

https://github.com/conorgil/2fa-notifier

2FA Notifier is a web extension that notifies users whether or not the sites they visit support two factor authentication (2FA).

2fa auth authentication chrome-extension chrome-extensions firefox-extension firefox-extensions firefox-webextension security twofa twofactor twofactorauth

Last synced: 05 May 2025

https://github.com/alecgn/crypthash-net

CryptHash.NET is a .NET multi-target library to encrypt/decrypt/hash/encode/decode strings and files, with an optional .NET Core multiplatform console utility.

aes argon2 authentication bcrypt c-sharp cbc cryptography csharp decode decryption dotnet dotnet-core dotnet-standard encode encryption gcm hash hmac password security

Last synced: 31 Jul 2025