Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/prowler-cloud/prowler

Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more

aws azure cis-benchmark cloud compliance devsecops forensics gcp gdpr hardening iam multi-cloud python security security-audit security-hardening security-tools well-architected

Last synced: 27 Jan 2025

https://github.com/google/oss-fuzz

OSS-Fuzz - continuous fuzzing for open source software.

fuzz-testing fuzzing oss-fuzz security stability vulnerabilities

Last synced: 27 Jan 2025

https://github.com/mvt-project/mvt

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

android forensics forensics-tools ios mobile security

Last synced: 27 Jan 2025

https://google.github.io/oss-fuzz/

OSS-Fuzz - continuous fuzzing for open source software.

fuzz-testing fuzzing oss-fuzz security stability vulnerabilities

Last synced: 15 Nov 2024

https://github.com/chaitin/xray

一款完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

passive-vulnerability-scanner poc security sqlinjection vulnerability vulnerability-scanner xss

Last synced: 01 Feb 2025

https://github.com/juice-shop/juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

24pullrequests application-security appsec ctf hacking hacktoberfest javascript owasp owasp-top-10 owasp-top-ten pentesting security vulnapp vulnerable

Last synced: 28 Jan 2025

https://github.com/kubescape/kubescape

Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

best-practice devops kubernetes mitre-attack nsa security vulnerability-detection

Last synced: 27 Jan 2025

https://github.com/armosec/kubescape

Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

best-practice devops kubernetes mitre-attack nsa security vulnerability-detection

Last synced: 05 Dec 2024

https://github.com/digininja/DVWA

Damn Vulnerable Web Application (DVWA)

dvwa hacking infosec php security sql-injection training

Last synced: 30 Oct 2024

https://github.com/digininja/dvwa

Damn Vulnerable Web Application (DVWA)

dvwa hacking infosec php security sql-injection training

Last synced: 28 Jan 2025

https://github.com/arkenfox/user.js

Firefox privacy, security and anti-tracking: a comprehensive user.js template for configuration and hardening

anti-fingerprinting anti-tracking arkenfox firefox mozilla privacy security settings

Last synced: 28 Jan 2025

https://github.com/helmetjs/helmet

Help secure Express apps with various HTTP headers

helmet http-headers javascript middleware security

Last synced: 30 Jan 2025

https://github.com/veeral-patel/how-to-secure-anything

How to systematically secure anything: a repository about security engineering

secure-design secure-systems security security-architecture security-assurance security-engineering threat-modeling

Last synced: 30 Jan 2025

https://github.com/trimstray/the-practical-linux-hardening-guide

This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).

audit centos checklist cis guide hardening linux linux-hardening linux-security manual openscap pci-dss redhat-enterprise-linux security

Last synced: 30 Jan 2025

https://github.com/gravitl/netmaker

Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.

cloud devsecops k8s kubernetes mesh mesh-network network networking overlay-network security self-hosted virtual-network virtual-networking vpn vpn-server wg-quick wireguard wireguard-ui wireguard-vpn zero-trust

Last synced: 27 Jan 2025

https://github.com/projectdiscovery/nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

bugbounty exploit-development exploits fingerprint hacktoberfest nuclei nuclei-checks nuclei-templates security vulnerability-detection

Last synced: 28 Jan 2025

https://github.com/crowdsecurity/crowdsec

CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.

attacks-prevention detection linux protection security

Last synced: 28 Jan 2025

https://bkimminich.github.io/juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

24pullrequests application-security appsec ctf hacking hacktoberfest javascript owasp owasp-top-10 owasp-top-ten pentesting security vulnapp vulnerable

Last synced: 27 Oct 2024

https://github.com/identityserver/identityserver4

OpenID Connect and OAuth 2.0 Framework for ASP.NET Core

aspnet-core dotnet identity identityserver4 oauth2 openid-connect security

Last synced: 18 Jan 2025

https://github.com/IdentityServer/IdentityServer4

OpenID Connect and OAuth 2.0 Framework for ASP.NET Core

aspnet-core dotnet identity identityserver4 oauth2 openid-connect security

Last synced: 25 Oct 2024

https://github.com/upgundecha/howtheysre

A curated collection of publicly available resources on how technology and tech-savvy organizations around the world practice Site Reliability Engineering (SRE)

alerting chaos-engineering dev-ops devops hacktoberfest hacktoberfest-accepted incident-management incident-response infrastructure ml-ops monitoring observability on-call post-mortem reliability security site-reliability-engineering software-engineering sre sre-culture

Last synced: 28 Jan 2025

https://github.com/monero-project/monero

Monero: the secure, private, untraceable cryptocurrency

blockchain c-plus-plus cmake cryptocurrency cryptography cryptonote monero p2p privacy security

Last synced: 28 Jan 2025

https://github.com/toniblyx/my-arsenal-of-aws-security-tools

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

auditing aws-infrastructure aws-inventory aws-lambda cloud cloudtrail dfir iam incident-response security security-tools

Last synced: 28 Jan 2025

https://github.com/samratashok/nishang

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

activedirectory hacking infosec nishang penetration-testing powershell red-team redteam security

Last synced: 28 Jan 2025

https://github.com/mailpile/mailpile

A free & open modern, fast email client with user-friendly encryption and privacy features

e-mail imap-client pgp search-engine security smtp-client tags

Last synced: 28 Jan 2025

https://github.com/mailpile/Mailpile

A free & open modern, fast email client with user-friendly encryption and privacy features

e-mail imap-client pgp search-engine security smtp-client tags

Last synced: 28 Oct 2024

https://github.com/bregman-arie/devops-resources

DevOps resources - Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP

aws bash checklists containers devops docker go interview jenkins linux mongo python questions security sql

Last synced: 28 Jan 2025

https://github.com/wpscanteam/wpscan

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via [email protected]

hacking-tool scan scanner security security-scanner wordpress wpscan wpvulndb

Last synced: 28 Jan 2025

https://github.com/jofpin/trape

People tracker on the Internet: OSINT analysis and research tool by Jose Pino

flask footprint hacking hacking-tool jose-pino osint phising python recognition security social-engineering tracking

Last synced: 28 Jan 2025

https://github.com/kishikawakatsumi/keychainaccess

Simple Swift wrapper for Keychain that works on iOS, watchOS, tvOS and macOS.

keychain security touch-id

Last synced: 27 Jan 2025

https://github.com/kishikawakatsumi/KeychainAccess

Simple Swift wrapper for Keychain that works on iOS, watchOS, tvOS and macOS.

keychain security touch-id

Last synced: 09 Dec 2024

https://github.com/linkedin/school-of-sre

At LinkedIn, we are using this curriculum for onboarding our entry-level talents into the SRE role.

git hadoop linux mysql networking nosql python security sre system-design

Last synced: 28 Jan 2025

https://github.com/simplex-chat/simplex-chat

SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱!

chat double-ratchet e2ee encryption haskell messaging privacy protocol security

Last synced: 28 Jan 2025

https://github.com/sensepost/objection

📱 objection - runtime mobile exploration

android framework frida instrumentation ios mobile pentest security

Last synced: 27 Jan 2025

https://github.com/capstone-engine/capstone

Capstone disassembly/disassembler framework for ARM, ARM64 (ARMv8), Alpha, BPF, Ethereum VM, HPPA, LoongArch, M68K, M680X, Mips, MOS65XX, PPC, RISC-V(rv32G/rv64G), SH, Sparc, SystemZ, TMS320C64X, TriCore, Webassembly, XCore and X86.

arm arm64 bpf disassembler ethereum framework m0s65xx m680x m68k mips powerpc reverse-engineering riscv security sparc systemz tms320c64x webassembly x86 x86-64

Last synced: 28 Jan 2025

https://github.com/unicorn-engine/unicorn

Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)

arm arm64 cpu cpu-emulator emulator framework m68k mips powerpc reverse-engineering riscv s390x security sparc systemz tricore x86 x86-64

Last synced: 27 Jan 2025

https://github.com/consensys/smart-contract-best-practices

A guide to smart contract security best practices

blockchain documentation ethereum security smart-contracts solidity

Last synced: 28 Jan 2025

https://consensys.github.io/smart-contract-best-practices/

A guide to smart contract security best practices

blockchain documentation ethereum security smart-contracts solidity

Last synced: 07 Nov 2024

https://github.com/knownsec/404starlink

404StarLink - 推荐优质、有意义、有趣、坚持维护的安全开源项目

opensource security tools

Last synced: 29 Jan 2025

https://github.com/knownsec/404StarLink

404StarLink - 推荐优质、有意义、有趣、坚持维护的安全开源项目

opensource security tools

Last synced: 29 Oct 2024

https://github.com/maxgoedjen/secretive

Store SSH keys in the Secure Enclave

mac secure-enclave security ssh

Last synced: 31 Jan 2025

https://github.com/Consensys/smart-contract-best-practices

A guide to smart contract security best practices

blockchain documentation ethereum security smart-contracts solidity

Last synced: 24 Oct 2024

https://github.com/ConsenSys/smart-contract-best-practices

A guide to smart contract security best practices

blockchain documentation ethereum security smart-contracts solidity

Last synced: 25 Oct 2024

https://github.com/OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

application-security appsec best-practices bugbounty guide hacking hacktoberfest owasp penetration-testing pentesting security

Last synced: 01 Nov 2024

https://github.com/owasp/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

application-security appsec best-practices bugbounty guide hacking hacktoberfest owasp penetration-testing pentesting security

Last synced: 31 Jan 2025

https://github.com/go-acme/lego

Let's Encrypt/ACME client and library written in Go

acme acme-client certificate dns letsencrypt rfc8555 rfc8737 rfc8738 security tls

Last synced: 27 Jan 2025

https://go-acme.github.io/lego/

Let's Encrypt/ACME client and library written in Go

acme acme-client certificate dns letsencrypt rfc8555 rfc8737 rfc8738 security tls

Last synced: 11 Nov 2024

https://github.com/frappe/frappe

Low code web framework for real world applications, in Python and Javascript

cms email erpnext frappe full-stack hacktoberfest javascript low-code mariadb multitenant postgres python rest-api security socket-io web-framework webhooks

Last synced: 28 Jan 2025

https://github.com/golang-jwt/jwt

Go implementation of JSON Web Tokens (JWT).

auth ed25519 go golang jwt security

Last synced: 27 Jan 2025

https://github.com/turbot/steampipe

Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.

aws azure cis cloud cnapp cspm devops devsecops etl gcp golang hacktoberfest kubernetes postgresql postgresql-fdw security sqlite steampipe terraform zero-etl

Last synced: 27 Jan 2025

https://github.com/presidentbeef/brakeman

A static analysis security vulnerability scanner for Ruby on Rails applications

brakeman rails ruby security security-audit security-tools security-vulnerability static-analysis vulnerabilities

Last synced: 27 Jan 2025

https://github.com/privatebin/privatebin

A minimalist, open source online pastebin where the server has zero knowledge of pasted data. Data is encrypted/decrypted in the browser using 256 bits AES.

crypto cryptography encrypted hacktoberfest one-time paste pastebin php security self-destroy self-hosted self-hosting

Last synced: 28 Jan 2025

https://github.com/telekom-security/tpotce

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

deception docker elk honeypot network-security security t-pot

Last synced: 28 Jan 2025

https://github.com/yokoffing/betterfox

Firefox user.js for speed, privacy, and security. Your favorite browser, but better.

anti-tracking firefox gecko mozilla performance privacy security settings speed tracking web-browser

Last synced: 28 Jan 2025

https://github.com/bee-san/pywhat

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙‍♀️

cyber cybersecurity hacking hacktoberfest malware malware-analysis malware-research pcap python re security tryhackme

Last synced: 28 Jan 2025

https://github.com/smallstep/certificates

🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.

acme acme-server ca certificate-authority certificates go pki security security-tools ssh tls x509

Last synced: 27 Jan 2025

https://github.com/nccgroup/scoutsuite

Multi-Cloud Security Auditing Tool

auditing aws azure cloud gcp security

Last synced: 27 Jan 2025

https://github.com/pycqa/bandit

Bandit is a tool designed to find common security issues in Python code.

bandit linter python security security-scanner security-tools static-code-analysis

Last synced: 27 Jan 2025

https://github.com/bee-san/pyWhat

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙‍♀️

cyber cybersecurity hacking hacktoberfest malware malware-analysis malware-research pcap python re security tryhackme

Last synced: 27 Oct 2024

https://github.com/nomi-sec/poc-in-github

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

cve exploit poc security vulnerability

Last synced: 30 Jan 2025

https://github.com/nomi-sec/PoC-in-GitHub

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

cve exploit poc security vulnerability

Last synced: 01 Nov 2024

https://github.com/arkime/arkime

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

big-data c javascript network-monitoring nsm packet-capture pcap security

Last synced: 28 Jan 2025

https://github.com/hwdsl2/docker-ipsec-vpn-server

Docker image to run an IPsec VPN server, with IPsec/L2TP, Cisco IPsec and IKEv2

cisco-ipsec docker docker-image encryption ikev2 ipsec l2tp libreswan linux network security vpn vpn-client vpn-server

Last synced: 28 Jan 2025

https://github.com/PrivateBin/PrivateBin

A minimalist, open source online pastebin where the server has zero knowledge of pasted data. Data is encrypted/decrypted in the browser using 256 bits AES.

crypto cryptography encrypted hacktoberfest one-time paste pastebin php security self-destroy self-hosted self-hosting

Last synced: 29 Oct 2024

https://github.com/virb3/wgcf

🚤 Cross-platform, unofficial CLI for Cloudflare Warp

client cloudflare plus security vpn warp wireguard

Last synced: 28 Jan 2025

https://github.com/zeek/zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

bro dfir network-monitoring nsm pcap security zeek

Last synced: 28 Jan 2025

https://github.com/PyCQA/bandit

Bandit is a tool designed to find common security issues in Python code.

bandit linter python security security-scanner security-tools static-code-analysis

Last synced: 26 Oct 2024

https://github.com/datreeio/datree

Prevent Kubernetes misconfigurations from reaching production (again 😤 )! From code to cloud, Datree provides an E2E policy enforcement solution to run automatic checks for rule violations. See our docs: https://hub.datree.io

admission-webhook best-practices cli datree devops guardrail kubernetes policy policy-management security static-code-analysis

Last synced: 15 Oct 2024

https://github.com/jeremylong/dependencycheck

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

ant-task build-tool gradle-plugin jenkins-plugin maven-plugin security security-audit software-composition-analysis vulnerability-detection

Last synced: 27 Jan 2025