An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/w5teams/w5

Security Orchestration, Automation and Response (SOAR) Platform. 安全编排与自动化响应平台,无需编写代码的安全自动化,使用 SOAR 可以让团队工作更加高效

automation devops hack hacker hacking python-script python3 security security-audit security-automation security-tools shuffle soar tools w5 w5soar walkoff

Last synced: 05 Apr 2025

https://github.com/cyfrin/security-and-auditing-full-course-s23

The ultimate, most advanced, security, DeFi, assembly, web3 auditor course ever created.

cryptocurrency ethereum security smart-contract-audit solidity

Last synced: 14 May 2025

https://github.com/stuxnet999/MemLabs

Educational, CTF-styled labs for individuals interested in Memory Forensics

ctf ctf-challenges cybersecurity dfir digital-forensics forensics memory-forensics security windows

Last synced: 13 Apr 2025

https://github.com/fullstackproltd/aspnetcorespa

Asp.Net 7.0 & Angular 15 SPA Fullstack application with plenty of examples. Live demo:

angular angular-cli aspnetcore aspnetcorespa best-practices compodoc efcore globalization identityserver4 security spa typescript unit-testing

Last synced: 15 May 2025

https://github.com/ascotbe/hackermind

各种安全相关思维导图整理收集。渗透步骤,web安全,CTF,业务安全,人工智能,区块链安全,数据安全,安全开发,无线安全,社会工程学,二进制安全,移动安全,红蓝对抗,运维安全,风控安全,linux安全

ctf hacker linux mind security

Last synced: 16 May 2025

https://github.com/DuendeSoftware/IdentityServer

The most flexible and standards-compliant OpenID Connect and OAuth 2.x framework for ASP.NET Core

aspnetcore identity oauth oidc openid-connect security

Last synced: 24 Mar 2025

https://github.com/DuendeSoftware/products

The most flexible and standards-compliant OpenID Connect and OAuth 2.x framework for ASP.NET Core

aspnetcore identity oauth oidc openid-connect security

Last synced: 29 Aug 2025

https://github.com/GoSecure/pyrdp

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

hacktoberfest honeypot mitm pentest pyrdp rdp security

Last synced: 13 Mar 2025

https://github.com/occlum/occlum

Occlum is a memory-safe, multi-process library OS for Intel SGX

cloud enclave intel-sgx os rust security

Last synced: 14 Jan 2026

https://github.com/hummerrisk/hummerrisk

HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。

cloud-custodian cloud-native cloud-native-security compliance compliance-as-code cspm k8s-security kubernetes-security prowler sbom security trivy vulnerability

Last synced: 14 May 2025

https://github.com/kubearmor/KubeArmor

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (BPF-LSM, AppArmor).

bpf containers ebpf hacktoberfest kernel kubernetes lsm policy sandbox security system tool

Last synced: 04 Apr 2025

https://github.com/bishopfox/gitgot

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

fuzzy-matching gist-search gists github-api osint python recon reconnaissance security security-scanner security-tools sensitive-data-exposure

Last synced: 08 Apr 2025

https://github.com/v-byte-cpu/sx

:vulcan_salute: Fast, modern, easy-to-use network scanner

arp docker go icmp infosec ipv4 lan network pentest proxy recon scan scanner security socks socks5 syn tcp udp wan

Last synced: 08 Apr 2025

https://github.com/BishopFox/GitGot

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

fuzzy-matching gist-search gists github-api osint python recon reconnaissance security security-scanner security-tools sensitive-data-exposure

Last synced: 02 Apr 2025

https://github.com/Ascotbe/HackerMind

各种安全相关思维导图整理收集。渗透步骤,web安全,CTF,业务安全,人工智能,区块链安全,数据安全,安全开发,无线安全,社会工程学,二进制安全,移动安全,红蓝对抗,运维安全,风控安全,linux安全

ctf hacker linux mind security

Last synced: 05 Apr 2025

https://github.com/psecio/iniscan

A php.ini scanner for best security practices

configuration ini php scanner security

Last synced: 14 May 2025

https://github.com/fullstackproltd/AspNetCoreSpa

Asp.Net 7.0 & Angular 15 SPA Fullstack application with plenty of examples. Live demo:

angular angular-cli aspnetcore aspnetcorespa best-practices compodoc efcore globalization identityserver4 security spa typescript unit-testing

Last synced: 16 Mar 2025

https://github.com/asadsahi/AspNetCoreSpa

Asp.Net 7.0 & Angular 15 SPA Fullstack application with plenty of examples. Live demo:

angular angular-cli aspnetcore aspnetcorespa best-practices compodoc efcore globalization identityserver4 security spa typescript unit-testing

Last synced: 05 Apr 2025

https://github.com/Cyfrin/security-and-auditing-full-course-s23

The ultimate, most advanced, security, DeFi, assembly, web3 auditor course ever created.

cryptocurrency ethereum security smart-contract-audit solidity

Last synced: 05 Apr 2025

https://github.com/byt3bl33d3r/SprayingToolkit

Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient

lync o365 owa password-spraying password-spraying-attacks pentesting python3 red-teams security security-tools skype-for-business

Last synced: 13 May 2025

https://github.com/xiecat/goblin

一款适用于红蓝对抗中的仿真钓鱼系统

blueteam cybersecurity goblin golang-tools honeypots phishing redteam redteam-tools security security-tools

Last synced: 08 Apr 2025

https://github.com/byt3bl33d3r/sprayingtoolkit

Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient

lync o365 owa password-spraying password-spraying-attacks pentesting python3 red-teams security security-tools skype-for-business

Last synced: 28 Sep 2025

https://github.com/scipag/hardeningkitty

HardeningKitty - Checks and hardens your Windows configuration

audit blueteam checklist defense hardening powershell registry security windows windows-10 windows-server

Last synced: 14 May 2025

https://github.com/0xhjk/dumpall

一款信息泄漏利用工具,适用于.git/.svn/.DS_Store泄漏和目录列出

bug-bounty dumpall githack hacking pentesting python3 scanner security spider svn tools

Last synced: 15 May 2025

https://github.com/Synzvato/decentraleyes

This repository has a new home: https://git.synz.io/Synzvato/decentraleyes

browser browser-extension cdn privacy security

Last synced: 02 Apr 2025

https://github.com/0xHJK/dumpall

一款信息泄漏利用工具,适用于.git/.svn/.DS_Store泄漏和目录列出

bug-bounty dumpall githack hacking pentesting python3 scanner security spider svn tools

Last synced: 02 Apr 2025

https://github.com/bert-janp/hunting-queries-detection-rules

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

azure blueteam cybersecurity defender-for-endpoint dfir infosec kql mde mdi misp security sentinel threat-hunting vulnerability-management zero-day

Last synced: 14 May 2025

https://github.com/synzvato/decentraleyes

This repository has a new home: https://git.synz.io/Synzvato/decentraleyes

browser browser-extension cdn privacy security

Last synced: 27 Sep 2025

https://github.com/lunasec-io/lunasec

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

compliance continuous-delivery cve-scanning cybersecurity dependency-analysis devsecops gdpr log4shell pci-dss sbom sbom-generator scanning scanning-tool security security-tools soc2 software-composition-analysis tokenization web-security zero-trust

Last synced: 15 May 2025

https://github.com/scipag/HardeningKitty

HardeningKitty - Checks and hardens your Windows configuration

audit blueteam checklist defense hardening powershell registry security windows windows-10 windows-server

Last synced: 09 Apr 2025

https://github.com/hwdsl2/wireguard-install

WireGuard VPN server installer for Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, Fedora, openSUSE and Raspberry Pi OS

bash centos debian encryption linux network raspberry-pi security shell ubuntu vpn vpn-client vpn-server wireguard

Last synced: 14 May 2025

https://github.com/IBM/fhe-toolkit-linux

IBM Fully Homomorphic Encryption Toolkit For Linux. This toolkit is a Linux based Docker container that demonstrates computing on encrypted data without decrypting it! The toolkit ships with two demos including a fully encrypted Machine Learning inference with a Neural Network and a Privacy-Preserving key-value search.

crypto cryptography encryption encryption-algorithms encryption-decryption ibm research research-tool security security-tools

Last synced: 13 Apr 2025

https://github.com/grapheneos/vanadium

Privacy and security enhanced releases of Chromium for GrapheneOS. Vanadium provides the WebView and standard user-facing browser on GrapheneOS. It depends on hardening in other GrapheneOS repositories and doesn't include patches not relevant to the build targets used on GrapheneOS.

android browser chromium grapheneos privacy security webview

Last synced: 16 Jan 2026

https://github.com/das-labor/panopticon

A libre cross-platform disassembler.

disassembler qml reverse-engineering rust security static-analysis

Last synced: 15 May 2025

https://github.com/pcaversaccio/reentrancy-attacks

A chronological and (hopefully) complete list of reentrancy attacks to date.

ethereum exploit reentrancy security smart-contracts solidity

Last synced: 14 May 2025

https://github.com/mufeedvh/moonwalk

Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.

cve exploit exploitation infosec infosectools linux privilege-escalation red-teaming redteam redteam-tools security security-tools

Last synced: 16 May 2025

https://github.com/ibm/fhe-toolkit-linux

IBM Fully Homomorphic Encryption Toolkit For Linux. This toolkit is a Linux based Docker container that demonstrates computing on encrypted data without decrypting it! The toolkit ships with two demos including a fully encrypted Machine Learning inference with a Neural Network and a Privacy-Preserving key-value search.

crypto cryptography encryption encryption-algorithms encryption-decryption ibm research research-tool security security-tools

Last synced: 27 Sep 2025

https://github.com/airbnb/binaryalert

BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.

aws lambda malware-detection security serverless terraform yara

Last synced: 15 May 2025

https://github.com/elementor/wp2static

WordPress static site generator for security, performance and cost benefits

github-page netlify security static-site-generator wordpress wordpress-plugin

Last synced: 13 Apr 2025

https://github.com/ge0rg3/requests-ip-rotator

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

apigateway aws bugbounty bypass hacktoberfest ip networking security security-tools web-security

Last synced: 13 Apr 2025

https://github.com/Ge0rg3/requests-ip-rotator

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

apigateway aws bugbounty bypass hacktoberfest ip networking security security-tools web-security

Last synced: 13 Apr 2025

https://github.com/hwdsl2/openvpn-install

OpenVPN server installer for Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, Fedora, openSUSE, Amazon Linux 2 and Raspberry Pi OS

bash centos debian encryption linux network openvpn raspberry-pi security shell ubuntu vpn vpn-client vpn-server

Last synced: 14 May 2025

https://github.com/syss-research/seth

Perform a MitM attack and extract clear text credentials from RDP connections

arp-spoofing mitm proof-of-concept rdp security

Last synced: 08 Apr 2025

https://github.com/SySS-Research/Seth

Perform a MitM attack and extract clear text credentials from RDP connections

arp-spoofing mitm proof-of-concept rdp security

Last synced: 07 Apr 2025

https://github.com/grapheneos/hardened_malloc

Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.

grapheneos hardening malloc malloc-library memory memory-allocation memory-allocator quarantine security slab-allocator

Last synced: 14 May 2025

https://github.com/baizesec/bylibrary

白阁文库是白泽Sec安全团队维护的一个漏洞POC和EXP公开项目

baize exp poc sec security

Last synced: 24 Mar 2025

https://github.com/BishopFox/jsluice

Extract URLs, paths, secrets, and other interesting bits from JavaScript

javascript security

Last synced: 10 May 2025

https://github.com/infrahq/infra

Infra provides authentication and access management to servers and Kubernetes clusters.

access go golang iam identity infra infrastructure kubernetes login oidc security

Last synced: 14 May 2025

https://github.com/intel/cve-bin-tool

The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.

cve cvss devsecops hacktoberfest python sbom sbom-tool security security-automation security-tools swrepo system-tools vulnerabilities vulnerability

Last synced: 13 May 2025

https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

azure blueteam cybersecurity defender-for-endpoint dfir infosec kql mde mdi misp security sentinel threat-hunting vulnerability-management zero-day

Last synced: 31 Mar 2025

https://github.com/felixgr/secure-ios-app-dev

Collection of the most common vulnerabilities found in iOS applications

ios security security-audit vulnerability-assessment

Last synced: 23 Mar 2025

https://github.com/advboxes/advbox

Advbox is a toolbox to generate adversarial examples that fool neural networks in PaddlePaddle、PyTorch、Caffe2、MxNet、Keras、TensorFlow and Advbox can benchmark the robustness of machine learning models. Advbox give a command line tool to generate adversarial examples with Zero-Coding.

adversarial-attacks adversarial-example adversarial-examples deep-learning deepfool fgsm graphpipe machine-learning onnx paddlepaddle security

Last synced: 08 Apr 2025

https://github.com/advboxes/AdvBox

Advbox is a toolbox to generate adversarial examples that fool neural networks in PaddlePaddle、PyTorch、Caffe2、MxNet、Keras、TensorFlow and Advbox can benchmark the robustness of machine learning models. Advbox give a command line tool to generate adversarial examples with Zero-Coding.

adversarial-attacks adversarial-example adversarial-examples deep-learning deepfool fgsm graphpipe machine-learning onnx paddlepaddle security

Last synced: 15 Mar 2025

https://github.com/cossacklabs/acra

Database security suite. Database proxy with field-level encryption, search through encrypted data, SQL injections prevention, intrusion detection, honeypots. Supports client-side and proxy-side ("transparent") encryption. SQL, NoSQL.

crypto cryptography database-proxy databases django encryption encryption-server golang honeypot intrusion-detection php python3 security

Last synced: 13 May 2025

https://github.com/GrapheneOS/hardened_malloc

Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.

grapheneos hardening malloc malloc-library memory memory-allocation memory-allocator quarantine security slab-allocator

Last synced: 08 May 2025

https://github.com/BaizeSec/bylibrary

白阁文库是白泽Sec安全团队维护的一个漏洞POC和EXP公开项目

baize exp poc sec security

Last synced: 11 Jul 2025

https://github.com/euphrat1ca/security-list

If you have any good suggestions or comments during the search process, please feedback some index experience in issues. Thank you for your participation.查阅过程中,如果有什么好的意见或建议,请在Issues反馈,感谢您的参与。

checklist geek kali security

Last synced: 26 Mar 2025

https://github.com/euphrat1ca/Security-List

If you have any good suggestions or comments during the search process, please feedback some index experience in issues. Thank you for your participation.查阅过程中,如果有什么好的意见或建议,请在Issues反馈,感谢您的参与。

checklist geek kali security

Last synced: 02 Apr 2025

https://github.com/cr0hn/dockerscan

Docker security analysis & hacking tools

docker docker-registry hacking registry scan security

Last synced: 15 May 2025

https://github.com/FSecureLABS/needle

The iOS Security Testing Framework

ios mobile needle pentesting python security

Last synced: 17 Aug 2025

https://aquasecurity.github.io/starboard/

Superseded by https://github.com/aquasecurity/trivy-operator

cloud-native custom-resource-definition kubernetes security starboard

Last synced: 08 May 2025

https://github.com/aquasecurity/starboard

Superseded by https://github.com/aquasecurity/trivy-operator

cloud-native custom-resource-definition kubernetes security starboard

Last synced: 12 May 2025

https://github.com/susam/mintotp

Minimal TOTP generator in 20 lines of Python

2fa cryptography hotp minimalist python3 security totp

Last synced: 14 May 2025

https://github.com/libressl/portable

LibreSSL Portable itself. This includes the build scaffold and compatibility layer that builds portable LibreSSL from the OpenBSD source code. Pull requests or patches sent to tech@openbsd.org are welcome.

c cryptography libressl openbsd openssl security ssl tls

Last synced: 11 Apr 2025

https://github.com/eliotsykes/rails-security-checklist

:key: Community-driven Rails Security Checklist (see our GitHub Issues for the newest checks that aren't yet in the README)

checklist rails rails-security rails-security-checklist ruby-on-rails security security-audit security-hardening

Last synced: 08 Apr 2025

https://github.com/reverseclabs/needle

The iOS Security Testing Framework

ios mobile needle pentesting python security

Last synced: 16 May 2025

https://github.com/ReversecLabs/needle

The iOS Security Testing Framework

ios mobile needle pentesting python security

Last synced: 10 May 2025

https://github.com/webpwnized/mutillidae

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.

10 application appsec cybersecurity owasp owasp-top-10 penetration-testing security top training web

Last synced: 14 May 2025

https://github.com/raikia/fiercephish

FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.

email hacking netsec phishing security

Last synced: 08 Apr 2025

https://github.com/Raikia/FiercePhish

FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.

email hacking netsec phishing security

Last synced: 02 Apr 2025

https://github.com/openclarity/openclarity

OpenClarity is an open source tool built to enhance security and observability of cloud native applications and infrastructure

cloud exploits kubernetes leaked-secrets malware rootkits sbom scanner security supply-chain virtual-machine vulnerabilities

Last synced: 15 Dec 2025

https://github.com/jeffzh3ng/fuxi

Penetration Testing Platform

penetration-testing pentest-tool security vulnerability

Last synced: 16 May 2025