Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/joychou93/java-sec-code

Java web common vulnerabilities and security code which is base on springboot and spring security

benchmark code cors deserialize java jsonp rce rmi security spel sqli ssrf tomcat web xxe

Last synced: 02 Jan 2025

https://github.com/pac4j/pac4j

Security engine for Java (authentication, authorization, multi frameworks): OAuth, CAS, SAML, OpenID Connect, LDAP, JWT...

authentication authorization cas dropwizard j2e java jax-rs jwt ldap oauth openid-connect play-framework ratpack saml security shiro sparkjava spring-mvc spring-security vertx

Last synced: 06 Jan 2025

https://github.com/conorpp/u2f-zero

U2F USB token optimized for physical security, affordability, and style

hardware security u2f

Last synced: 04 Jan 2025

https://github.com/JoyChou93/java-sec-code

Java web common vulnerabilities and security code which is base on springboot and spring security

benchmark code cors deserialize java jsonp rce rmi security spel sqli ssrf tomcat web xxe

Last synced: 21 Nov 2024

https://github.com/brendan-rius/c-jwt-cracker

JWT brute force cracker written in C

brute-force cracker jwt-authentication security

Last synced: 04 Jan 2025

https://github.com/blackorbird/APT_REPORT

Interesting APT Report Collection And Some Special IOC

apt cybersecurity malware security threat-hunting

Last synced: 06 Nov 2024

https://github.com/OpenSC/OpenSC

Open source smart card tools and middleware. PKCS#11/MiniDriver/Tokend

c minidriver opensc pkcs11 security smartcard tokend

Last synced: 27 Oct 2024

https://github.com/outflanknl/redelk

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

elastic elasticsearch kibana logstash monitoring red-teaming security siem

Last synced: 01 Jan 2025

https://github.com/ajinabraham/nodejsscan

nodejsscan is a static security code scanner for Node.js applications.

code-analysis code-review devsecops javascript lint node node-security nodejs nodejsscan sast security security-scanner static-analysis

Last synced: 02 Jan 2025

https://github.com/netwrix/pingcastle

PingCastle - Get Active Directory Security at 80% in 20% of the time

active-directory ciso dod hipaa mimikatz nist ping-castle pingcastle reporting-tool security sox stig

Last synced: 02 Jan 2025

https://github.com/outflanknl/RedELK

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

elastic elasticsearch kibana logstash monitoring red-teaming security siem

Last synced: 21 Nov 2024

https://github.com/googleprojectzero/winafl

A fork of AFL for fuzzing Windows binaries

afl fuzzing security

Last synced: 02 Jan 2025

https://github.com/fisco-bcos/fisco-bcos

FISCO BCOS(发音为/ˈfɪskl bi:ˈkɒz/)是一个稳定、高效、安全的许可区块链平台,已被广泛应用于现实的行业应用。截至目前,已拥有5000多家企事业单位,400多个产业数字化标杆应用,涵盖文化版权、司法服务、政府服务、物联网、金融、智慧社区、房地产建设、社区治理、乡村振兴等领域。FISCO BCOS (pronounced /ˈfɪskl bi:ˈkɒz/) is a stable, efficient, and secure permissioned blockchain platform that has been widely used in real-world industry applications.

bcos blockchain consensus consortium crud crypto evm fintech fisco fisco-bcos p2p pbft precompiled raft rpc security solidity synchronization zero-knowledge

Last synced: 02 Jan 2025

https://github.com/FISCO-BCOS/FISCO-BCOS

FISCO BCOS(发音为/ˈfɪskl bi:ˈkɒz/)是一个稳定、高效、安全的许可区块链平台,已被广泛应用于现实的行业应用。截至目前,已拥有5000多家企事业单位,400多个产业数字化标杆应用,涵盖文化版权、司法服务、政府服务、物联网、金融、智慧社区、房地产建设、社区治理、乡村振兴等领域。FISCO BCOS (pronounced /ˈfɪskl bi:ˈkɒz/) is a stable, efficient, and secure permissioned blockchain platform that has been widely used in real-world industry applications.

bcos blockchain consensus consortium crud crypto evm fintech fisco fisco-bcos p2p pbft precompiled raft rpc security solidity synchronization zero-knowledge

Last synced: 30 Oct 2024

https://github.com/duoergun0729/nlp

兜哥出品 <一本开源的NLP入门书籍>

ai fasttext nlp security word2vec

Last synced: 04 Jan 2025

https://github.com/yzcheng90/x-springboot

X-SpringBoot是一个轻量级的Java快速开发平台,能快速开发项目并交付【接私活利器】

minio mybatis-plus redis restful security spring-boot spring-mvc springmvc-java-web springmvc-mybatis swagger

Last synced: 01 Jan 2025

https://github.com/ory/fosite

Extensible security first OAuth 2.0 and OpenID Connect SDK for Go.

auth authentication authorization golang hacktoberfest library oauth oauth2 openid-connect sdk security

Last synced: 06 Jan 2025

https://github.com/wolfSSL/wolfssl

The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS 1.3!

c-library cipher-suites cryptography cryptography-api dtls embedded-systems encryption fips https iot openssl openssl-alternative openssl-api security sniffer ssl tls tls13 trusted-execution-environment wolfssl

Last synced: 05 Nov 2024

https://github.com/wolfssl/wolfssl

The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS 1.3!

c-library cipher-suites cryptography cryptography-api dtls embedded-systems encryption fips https iot openssl openssl-alternative openssl-api security sniffer ssl tls tls13 trusted-execution-environment wolfssl

Last synced: 07 Jan 2025

https://github.com/authpass/authpass

AuthPass - Password Manager based on Flutter for all platforms. Keepass 2.x (kdbx 3.x) compatible.

android contributions-welcome dart dartlang debian flutter flutter-apps hacktoberfest help-wanted ios kdbx keepass linux macos-application password-manager password-store security web windows

Last synced: 01 Jan 2025

https://github.com/onionbrowser/onionbrowser

An open-source, privacy-enhancing web browser for iOS, utilizing the Tor anonymity network

anonymity browser ios mobile mpl objective-c onion privacy security tor tor-network web-browser

Last synced: 01 Jan 2025

https://ajinabraham.github.io/NodeJsScan

nodejsscan is a static security code scanner for Node.js applications.

code-analysis code-review devsecops javascript lint node node-security nodejs nodejsscan sast security security-scanner static-analysis

Last synced: 13 Oct 2024

https://github.com/keystone-engine/keystone

Keystone assembler framework: Core (Arm, Arm64, Hexagon, Mips, PowerPC, Sparc, SystemZ & X86) + bindings

arm arm64 assembler framework hexagon mips powerpc reverse-engineering security sparc systemz x86 x86-64

Last synced: 07 Jan 2025

https://github.com/solokeys/solo1

Solo 1 firmware in C

fido2 hardware security u2f webauthn

Last synced: 04 Jan 2025

https://github.com/az0x7/vulnerability-checklist

This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter

bugbounty security sqlinjection vulnerability vulnerability-checklist web-vulnerability

Last synced: 29 Nov 2024

https://github.com/guardianproject/orbot

The Github home of Orbot: Tor on Android (Also available on gitlab!)

anonymity anticensorship censorship-circumvention security tor

Last synced: 01 Jan 2025

https://github.com/rsmusllp/king-phisher

Phishing Campaign Toolkit

king-phisher phishing python security

Last synced: 02 Jan 2025

https://github.com/OnionBrowser/OnionBrowser

An open-source, privacy-enhancing web browser for iOS, utilizing the Tor anonymity network

anonymity browser ios mobile mpl objective-c onion privacy security tor tor-network web-browser

Last synced: 24 Oct 2024

https://github.com/unrolled/secure

HTTP middleware for Go that facilitates some quick security wins.

go golang middleware security

Last synced: 06 Jan 2025

https://github.com/unikraft/unikraft

A next-generation cloud native kernel designed to unlock best-in-class performance, security primitives and efficiency savings.

application cloud cloud-native hacktoberfest kernel library microservice operating-system os osdev performance qemu security unikernel unikernels unikraft virtualization

Last synced: 01 Nov 2024

https://github.com/Yamato-Security/hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

attack cybersecurity detection dfir event forensics hayabusa hunting incident incident-response logs response rust security security-automation sigma threat threat-hunting windows yamato

Last synced: 03 Nov 2024

https://github.com/coreruleset/coreruleset

OWASP CRS (Official Repository)

crs owasp ruleset security

Last synced: 29 Oct 2024

https://github.com/find-sec-bugs/find-sec-bugs

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

bytecode code-analysis cwe findbugs hacktoberfest java owasp security security-audit static-analysis taint-analysis

Last synced: 30 Oct 2024

https://github.com/TokTok/c-toxcore

The future of online communications.

cryptography encryption network p2p security toxcore

Last synced: 03 Nov 2024

https://github.com/arch3rpro/pentest-windows

Windows11 Penetration Suite Toolkit 一个开箱即用的windows渗透测试环境

pentesting pentesting-tools pentesting-windows security security-tools

Last synced: 04 Dec 2024

https://github.com/onury/accesscontrol

Role and Attribute based Access Control for Node.js

abac access-control acl attributes authorization nodejs permissions rbac roles security

Last synced: 07 Jan 2025

https://github.com/arch3rPro/Pentest-Windows

Windows11 Penetration Suite Toolkit 一个开箱即用的windows渗透测试环境

pentesting pentesting-tools pentesting-windows security security-tools

Last synced: 05 Nov 2024

https://github.com/rabbitstack/fibratus

Adversary tradecraft detection, protection, and hunting

adversary blueteam edr etw golang instrumentation python security windows windows-kernel

Last synced: 07 Jan 2025

https://github.com/palahsu/ddos-ripper

DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic

attack-defense attack-server ddos ddos-attack ddos-attack-tool ddos-attack-tools ddos-attacks ddos-protection ddos-ripper ddos-tool deface-website denial-of-service hacking-tool hacking-tools internet-traffic linux-tools protection security sql-injection web-security

Last synced: 01 Jan 2025

https://github.com/praetorian-inc/gokart

A static analysis tool for securing Go code

golang security security-tools static-analysis static-code-analysis

Last synced: 26 Sep 2024

https://github.com/mozilla/mozdef

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

abandoned elasticsearch elk elk-stack python security siem unmaintained

Last synced: 28 Sep 2024

https://github.com/mozilla/MozDef

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

abandoned elasticsearch elk elk-stack python security siem unmaintained

Last synced: 27 Oct 2024

https://github.com/ngc660sec/NGCBot

一个基于✨HOOK机制的微信机器人,支持🌱安全新闻定时推送【FreeBuf,先知,安全客,奇安信攻防社区】,👯Kfc文案,⚡备案查询,⚡手机号归属地查询,⚡WHOIS信息查询,🎉星座查询,⚡天气查询,🌱摸鱼日历,⚡微步威胁情报查询, 🐛美女视频,⚡美女图片,👯帮助菜单。📫 支持积分功能,⚡支持自动拉人,⚡检测广告,🌱自动群发,👯Ai回复,😄自定义程度丰富,小白也可轻松上手!

bot crawler security wei-xin weixin wxbot

Last synced: 29 Oct 2024

https://github.com/pglombardo/passwordpusher

🔐 Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.

communicate-passwords docker-container encryption hacktoberfest information-technology netsec netsec-tools openshift-templates password password-expiration password-pusher password-safety ruby secret security security-tools self-hosted

Last synced: 01 Jan 2025

https://github.com/gautamkrishnar/nothing-private

Do you think you are safe using private browsing or incognito mode?. :smile: :imp: This will prove that you're wrong. Previously hosted at nothingprivate.ml

browser-fingerprinting browsers fingerprinting google-analytics hacktoberfest icognito-mode privacy private-browsing proof-of-concept security website

Last synced: 04 Jan 2025

https://github.com/palahsu/DDoS-Ripper

DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic

attack-defense attack-server ddos ddos-attack ddos-attack-tool ddos-attack-tools ddos-attacks ddos-protection ddos-ripper ddos-tool deface-website denial-of-service hacking-tool hacking-tools internet-traffic linux-tools protection security sql-injection web-security

Last synced: 05 Nov 2024

https://github.com/evilsocket/xray

XRay is a tool for recon, mapping and OSINT gathering from public networks.

intelligence mapping network osint security shodan

Last synced: 04 Jan 2025

https://github.com/codingo/reconnoitre

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.

discover-services enumeration hacking hacking-tool kali-linux nmap offensive-security oscp penetration-testing range scanner scanning security security-audit security-scanner security-tools service-enumeration services-discovered snmp virtual-hosts

Last synced: 04 Jan 2025

https://github.com/codingo/Reconnoitre

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.

discover-services enumeration hacking hacking-tool kali-linux nmap offensive-security oscp penetration-testing range scanner scanning security security-audit security-scanner security-tools service-enumeration services-discovered snmp virtual-hosts

Last synced: 01 Nov 2024

https://github.com/pucherot/pi.alert

WIFI / LAN intruder detector. Check the devices connected and alert you with unknown devices. It also warns of the disconnection of "always connected" devices

adminlte arp-scan dnsmasq ids intrusion-detection lan mac-address network pi-hole scan security wifi

Last synced: 04 Jan 2025

https://github.com/kata-containers/runtime

Kata Containers version 1.x runtime (for version 2.x see https://github.com/kata-containers/kata-containers).

container containers cri-o docker k8s kubernetes kvm oci qemu security virtual-machine virtualization

Last synced: 27 Sep 2024

https://github.com/crev-dev/cargo-crev

A cryptographically verifiable code review system for the cargo (Rust) package manager.

code code-review decentralized p2p review scalable security trust

Last synced: 07 Jan 2025

https://github.com/bytedance/elkeid

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.

cwpp edr hids linux-security rasp security

Last synced: 03 Jan 2025

https://github.com/bytedance/Elkeid

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.

cwpp edr hids linux-security rasp security

Last synced: 01 Nov 2024

https://github.com/scalad/note

常规Java工具,算法,加密,数据库,面试题,源代码分析,解决方案

java linux mysql security utils

Last synced: 04 Jan 2025

https://github.com/owasp/owasp-masvs

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

android-app audit gitbook ios-app mastg masvs mobile mstg owasp penetration-testing penetration-tests security security-audit security-standards standard verification

Last synced: 02 Jan 2025

https://github.com/inonshk/31-days-of-API-Security-Tips

This challenge is Inon Shkedy's 31 days API Security Tips.

api-pentest api-security bug-bounty bugbounty bugbountytips infosec pentest security

Last synced: 26 Oct 2024

https://github.com/jtpereyda/boofuzz

A fork and successor of the Sulley Fuzzing Framework

fuzzing python security

Last synced: 07 Jan 2025

https://github.com/pglombardo/PasswordPusher

🔐 Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.

communicate-passwords docker-container encryption hacktoberfest information-technology netsec netsec-tools openshift-templates password password-expiration password-pusher password-safety ruby secret security security-tools self-hosted

Last synced: 03 Nov 2024

https://github.com/cncf/tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!

access-control assessment cloud-native cncf safety secure-access security

Last synced: 29 Dec 2024

https://github.com/zhzyker/dismap

Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点

cybersecurity detection fingerprint fingerprint-scanner golang-tools identification pentest-tool pentest-tools redteam redteam-tools security security-scan security-tools webscan

Last synced: 03 Jan 2025

https://github.com/owasp/api-security

OWASP API Security Project

api documentation-portal owasp-top security web-api

Last synced: 03 Dec 2024

https://github.com/OWASP/owasp-masvs

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

android-app audit gitbook ios-app mastg masvs mobile mstg owasp penetration-testing penetration-tests security security-audit security-standards standard verification

Last synced: 30 Oct 2024

https://github.com/OWASP/API-Security

OWASP API Security Project

api documentation-portal owasp-top security web-api

Last synced: 25 Oct 2024

https://github.com/bank-vaults/bank-vaults

A Vault swiss-army knife: A CLI tool to init, unseal and configure Vault (auth methods, secret engines).

alibaba-cloud amazon azure golang google-cloud helm-chart hsm istio kubernetes kubernetes-secrets mutating-webhook operator secret security unseal vault vault-client vault-operator vault-unsealing

Last synced: 02 Jan 2025

https://github.com/bhavsec/reconspider

🔎 Most Advanced Open Source Intelligence (OSINT) Framework for scanning IP Address, Emails, Websites, Organizations.

automated cybersecurity framework hacking information-gathering osint pentest pentesting python recon reconnaissance scanner security

Last synced: 30 Oct 2024

https://github.com/pucherot/Pi.Alert

WIFI / LAN intruder detector. Check the devices connected and alert you with unknown devices. It also warns of the disconnection of "always connected" devices

adminlte arp-scan dnsmasq ids intrusion-detection lan mac-address network pi-hole scan security wifi

Last synced: 31 Oct 2024

https://github.com/salesforce/cloudsplaining

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

aws aws-iam aws-security cloud cloud-security hacktoberfest iam salesforce security

Last synced: 07 Jan 2025

https://github.com/awslabs/aws-well-architected-labs

Hands on labs and code to help you learn, measure, and build using architectural best practices.

aws cost lab reliability reliability-engineering resilience resiliency security well-architected wellarchitected

Last synced: 02 Jan 2025

https://github.com/cisagov/malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

arkime cybersecurity infosec network-security network-traffic-analysis networksecurity networktrafficanalysis opensearch opensearch-dashboards pcap security suricata zeek

Last synced: 02 Jan 2025

https://github.com/walidshaari/certified-kubernetes-security-specialist

Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.

apparmor certification cks ckss exam-objectives falco kernel-hardening kube-bench kube-hunter kubernetes kubernetes-security mitre-attack open-policy-agent os-footprint pod pod-security-policy policy seccomp security trivy

Last synced: 01 Jan 2025

https://github.com/ttlequals0/autovpn

Create On Demand Disposable OpenVPN Endpoints on AWS.

autovpn aws openvpn openvpn-configuration openvpn-endpoints privacy security vpn vpn-server

Last synced: 05 Jan 2025

https://github.com/aress31/burpgpt

A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.

ai burp-extensions burp-plugin burpsuite burpsuite-extender cybersecurity gpt gpt-3 openai openai-api pentesting security security-automation webapp

Last synced: 02 Jan 2025

https://github.com/netflix-skunkworks/stethoscope

Personalized, user-focused recommendations for employee information security.

education security user-focused-security

Last synced: 04 Jan 2025

https://github.com/dliv3/venom

Venom - A Multi-hop Proxy for Penetration Testers

ctf golang pentest-tool pentesting port-forward port-reuse proxy redteam security socks5 ssh-tunnel tunnel venom

Last synced: 04 Jan 2025

https://github.com/Dliv3/Venom

Venom - A Multi-hop Proxy for Penetration Testers

ctf golang pentest-tool pentesting port-forward port-reuse proxy redteam security socks5 ssh-tunnel tunnel venom

Last synced: 01 Nov 2024

https://github.com/Netflix-Skunkworks/stethoscope

Personalized, user-focused recommendations for employee information security.

education security user-focused-security

Last synced: 03 Nov 2024

https://github.com/itext/itext-java

iText for Java represents the next level of SDKs for developers that want to take advantage of the benefits PDF can bring. Equipped with a better document engine, high and low-level programming capabilities and the ability to create, edit and enhance PDF documents, iText can be a boon to nearly every workflow.

accessibility acroform archiving ccpa digital-signature documents encryption gdpr itext library pades pades-standard pdf pdf-generation pdfa pdfua sdk security svg xfdf

Last synced: 02 Jan 2025

https://github.com/sensiolabs/security-checker

PHP frontend for security.symfony.com

composer php security

Last synced: 29 Sep 2024

https://github.com/0xbug/hawkeye

GitHub 泄露监控系统(GitHub Sensitive Information Leakage Monitor Spider)

github leakage security

Last synced: 04 Jan 2025

https://github.com/walidshaari/Certified-Kubernetes-Security-Specialist

Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.

apparmor certification cks ckss exam-objectives falco kernel-hardening kube-bench kube-hunter kubernetes kubernetes-security mitre-attack open-policy-agent os-footprint pod pod-security-policy policy seccomp security trivy

Last synced: 15 Nov 2024

https://github.com/0xbug/Hawkeye

GitHub 泄露监控系统(GitHub Sensitive Information Leakage Monitor Spider)

github leakage security

Last synced: 29 Oct 2024

https://github.com/cider-security-research/cicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

appsec cicd ctf devops devsecops gitlab infosec jenkins security

Last synced: 04 Jan 2025

https://github.com/square/ghostunnel

A simple SSL/TLS proxy with mutual authentication for securing non-TLS services.

crypto go hsm keychain pkcs11 proxy security ssl stunnel tls tunnel

Last synced: 09 Dec 2024