An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/prontolabs/pronto-brakeman

Pronto runner for Brakeman, security vulnerability scanner for RoR

analyzer brakeman pronto pronto-runner ruby-on-rails security security-scanner

Last synced: 24 Oct 2025

https://github.com/reinershir/lui-auth

一个使用简单的安全防护、权限验证、身份验证工具,无复杂配置,只需依赖jar并简单配置即可使用,目前拥有功能:角色、菜单、权限集成管理,IP限流,内部服务双向验证、自动打印请求日志等。 A simple and secure protection tool that is easy to use, with permission verification and identity authentication. No complex configuration is required, just rely on the jar file and simple configuration to use it.

authentication-backend lui-auth modified-preorder-tree-traversal permission security

Last synced: 14 Jan 2026

https://github.com/yosaiproject/yosai_alchemystore

SQLAlchemy-enabled Account Store for Yosai that features a flat Role-Based Access Control (RBAC) data model

security sqlalchemy yosai

Last synced: 14 Jan 2026

https://github.com/thejefflarson/soundcheck

Simple security reviews for AI agents

llms security skills

Last synced: 10 Jun 2026

https://github.com/advanced-security/probot-security-alerts

Sample GitHub App which monitors and enforces rules for code scanning, Dependabot, and secret scanning alerts

ghas nodejs probot sample security security-alerts typescript

Last synced: 23 Oct 2025

https://github.com/veinar/envcloak

A secure and easy-to-use tool for managing sensitive data with built-in encryption, decryption, and key management. Protect your secrets during development, testing, and deployment with CLI command + Python library support.

cicd cicd-pipeline cli-tool decryption devops encryption encryption-decryption env environment-variables python-library secret-management secret-sharing secrets security sensitive-data-security tool tooling tools validation

Last synced: 11 Sep 2025

https://github.com/melonattacker/threat-thinker

AI-powered threat modeling that turns architecture diagrams into actionable risks

architecture diagrams python risk-analytics security security-tools threat-analysis threat-modelling

Last synced: 02 Apr 2026

https://github.com/dutchcoders/identify

Identify web application versions

fingerprint security

Last synced: 11 Apr 2025

https://github.com/ctxz/mkauthdocs

A tool made to implement simple authentication on top of mkdocs builds.

auth authentication credentials login mkdocs security

Last synced: 21 Mar 2025

https://github.com/sitebatch/waffle-go

Waffle is a library for integrating a Web Application Firewall (WAF) into Go applications.

golang security waf

Last synced: 12 Jan 2026

https://github.com/ko-ko-ko/php-assert

Fast flexible php assert

assert php security validation

Last synced: 11 Jan 2026

https://github.com/fphammerle/docker-onion-service

hidden tor .onion service 🐳

docker network onion-service podman security tor

Last synced: 04 May 2025

https://github.com/akshatvg/vulnerability-testing-solutions

Website for testing and preventing different attacks like XSS, SQL Injection & Spoofing for Nasscom (ISAA) Project.

audit cyber-security security spoofing sql-injection testing vulnerability website xss

Last synced: 11 Apr 2025

https://github.com/FrozenAssassine/EasePass

A powerful but simple, password manager that stores all your passwords locally and offline. Written in C# WinUI3

2fa-client 2factor app csharp password password-manager passwordmanager security totp windows winui3

Last synced: 31 Mar 2025

https://github.com/rasoolsomji/django-security

Django is great! Here are some ways to make it safer

audit csrf cybersecurity django nginx owasp pentest python security vulnerabilities xss

Last synced: 14 Mar 2025

https://github.com/plackemacher/secure_compare

A secure compare for Elixir.

elixir library package security

Last synced: 12 Apr 2025

https://github.com/sebastienrousseau/password-generator

A fast, simple, and powerful open-source utility tool for generating strong, unique, and random passwords. The Password Generator supports various types of passwords including base64-encoded, memorable, and complex strong passwords.

crypto cryptography dictionary dictionary-tools generator javascript memorable-passphrases memorable-passwords nodejs npm passgen passgenerator password password-generator passwords security security-tools yeoman

Last synced: 16 Mar 2025

https://github.com/luizbizzio/siteguard

🛡️ A JavaScript utility that detects when developer tools are opened in web browsers. It blocks right-click actions, drag events, and certain keyboard shortcuts to enhance the protection of web content from unauthorized inspection or tampering.

blocker content-protection copy detector devtools iot javascript legacy library lock open-source prevent privacy safety script security siteguard web web-tools website

Last synced: 27 Apr 2025

https://github.com/sap-samples/cross-language-detection-artifacts

This repository complements our paper by offering the training dataset, the best-performing models utilized in our real-world experiment, the list of identified malicious packages, and the scripts necessary to replicate and verify our results.

machine-learning open-source sample sample-code security

Last synced: 13 Apr 2025

https://github.com/yallxe/hogg

Common vulnerability scanning on steroids ☄️

dns exploit network proxy rust rust-lang scanner secrets security sniffer vulnerabilities webscanner

Last synced: 19 Jul 2025

https://github.com/Ovi3/awvs_xray

AWVS13和xray的自动化扫描脚本

scanner-web security vulnerability vulnerability-scanners web-security

Last synced: 11 Jul 2025

https://github.com/ph4r05/tinyosids

Intrusion Detection System (IDS) for Wireless Sensor Networks (WSN)

ids iot research security tinyos

Last synced: 11 Jul 2025

https://github.com/dl-solarity/audits

Distributed Lab public Solidity audits

auditing security solarity solidity

Last synced: 31 Oct 2025

https://github.com/sjinks/ssh-honeypotd

A low-interaction SSH honeypot written in C

honeypot security ssh ssh-honeypot ssh-honeypotd

Last synced: 27 Jun 2025

https://github.com/artginzburg/2fatotray

 Copy 2FA tokens in a click (macOS)

2fa app macos security totp

Last synced: 31 Aug 2025

https://github.com/bbva/gitsec

gitsec: GIT Secret Discovery

dvcs secrets security

Last synced: 15 Aug 2025

https://github.com/offa/keygen

KeyGen is a generator for keys and passwords.

c c11 cmake key-generator openssl password-generator security

Last synced: 14 May 2025

https://github.com/rapidlua/sandals

A lightweight process isolation tool, requiring absolutely no privileges to run

cgroups-v2 chroot linux linux-namespaces process-isolation sandbox seccomp-bpf security

Last synced: 30 Mar 2025

https://github.com/beevik/nts

network time security client package for go

go ntp ntp-client ntp-protocol nts nts-client nts-protocol security time

Last synced: 12 Apr 2025

https://github.com/neuralegion/sslscanner

SSL Scanner written in Crystal

crystal openssl scanner security ssl

Last synced: 07 May 2025

https://github.com/tjenkinson/gh-action-auto-merge-dependency-updates

A GitHub action that will automatically approve and merge a PR that only contains dependency updates, based on some rules. Also possible to disable the merge and use the `success` output to use in combination with other actions.

action automation automerge dependabot dependency gh-action merge security updater

Last synced: 06 Apr 2025

https://github.com/CharlesAverill/DEFFS

Distributed, Encrypted, Fractured File System - A custom distributed file system written in C with FUSE

filesystem fuse linux security

Last synced: 06 Mar 2025

https://github.com/valpackett/pysectools

A small Python library that contains various security things

python security unix

Last synced: 22 Apr 2025

https://github.com/sripwoud/ethernaut

🧑‍🚀 Web3/Solidity based wargame, played in the Ethereum Virtual Machine

blockchain ctf ethereum ethernaut evm forge foundry hack security solidity web3

Last synced: 16 Mar 2026

https://github.com/neuralegion/sectester-js-demo

This is a demo project for the SecTester JS SDK framework, with some installation and usage examples.

appsec brightsec demo e2e jest nestjs pentesting qa security test testing typescript

Last synced: 05 Apr 2025

https://github.com/Azure/AzureKeyVault

R interface to Azure Key Vault

azure azure-key-vault azure-sdk-r r security

Last synced: 29 Jul 2025

https://github.com/wookey-project/manifest

The WooKey project manifest repository, use repo init -u https://github.com/wookey-project/manifest.git

embedded iot security wookey

Last synced: 22 Feb 2026

https://github.com/geminishkv/course_labs

Лабораторные работы по курсам для AppSec, Risk Analysis, Securty Champion: Toolchain, Orchestration, CI/CD, UML, etc.

appsec appsec-tutorials bash bmstu containersecurity course dast docker growth-team lerning-platform owasp-top-10 python sast sca secretdetection security security-team-testing toolchain tools training-materials

Last synced: 01 Apr 2026

https://github.com/postgrespro/libblobstamper

Framework for Structure Aware Fuzzing. Allows to build own stamps that would convert pulp-data that came from fuzzer to data with structure you need

fuzzing sdl security structure-aware-fuzzing

Last synced: 28 Feb 2026

https://github.com/syntatis/wp-feature-flipper

🚥 Disable Comments, Gutenberg, Emojis, and other features you don't need in WordPress®

comments emojis gutenberg media-library rss-feed security wordpress-plugin wp-admin xmlrpc

Last synced: 10 Oct 2025

https://github.com/paulveillard/cybersecurity-ssrf

An ongoing & curated collection of awesome web vulnerability - Server-side request forgery software practices and remediation, libraries and frameworks, best guidelines and technical resources about SSRF

cybersecurity mitigation remediation security security-tools server-side server-side-request-forgery ssrf vulnerabilities vulnerability vulnerability-assessment vulnerability-detection vulnerability-management

Last synced: 08 Oct 2025

https://github.com/mondoohq/samples

Security Scanning Samples with cnspec, cnquery, and Mondoo Platform

hacking protect samples security security-as-code

Last synced: 19 Mar 2026

https://github.com/jenkinsci/authorize-project-plugin

Run a job with specified authorization

adopt-this-plugin jenkins-plugin security

Last synced: 11 May 2026

https://github.com/karib0u/rustinel-rules

Official, curated detection content (Sigma, YARA, IOC packs) for the Rustinel endpoint detection engine.

blue-team detection-as-code detection-engineering edr incident-response ioc mitre-attack rustinel security sigma threat-detection yara

Last synced: 29 Jun 2026

https://github.com/cocopuff2u/macos_admin_scripts

macOS Admin Script/Tool Collection

jamf macos mdm scripts security

Last synced: 01 Apr 2026

https://gitlab.com/i2pplus/I2P.Plus

I2P+ is a soft-fork of the Java I2P Anonymizing Network Layer. License: AGPL v.3 https://i2pplus.github.io/

anonymity privacy security

Last synced: 13 Jun 2025

https://github.com/rsc-dev/ishtar

.NET applications hacking toolset

c-sharp dll-injection hacking security

Last synced: 23 Jul 2025

https://github.com/zaproxy/action-af

A GitHub Action for running ZAP Automation Framework plans

actions dast devsecops github-actions security

Last synced: 30 Jun 2025

https://github.com/vita-group/random-shuffling-backdoordetect

[NeurIPS 2022] "Randomized Channel Shuffling: Minimal-Overhead Backdoor Attack Detection without Clean Datasets" by Ruisi Cai*, Zhenyu Zhang*, Tianlong Chen, Xiaohan Chen, Zhangyang Wang

backdoor-attacks deep-learning python pytorch security trojan

Last synced: 19 Apr 2025

https://github.com/dev-sec/chef-jenkins-hardening

⛔ DEPRECATED: A secure jenkins installation

chef chef-cookbook devops hardening jenkins security

Last synced: 01 Apr 2025

https://github.com/thomasmerz/pihole-wireguard-knowhow

My Setup for Pi-hole at home and in the cloud to be used with WireGuard for the whole family.

anti-ads anti-malware anti-spyware anti-surveillance anti-tracking dns privacy security vpn

Last synced: 01 Apr 2025

https://github.com/openagentidentityprotocol/agentidentityprotocol

Agent Identity Protocol - Zero-trust security layer for AI agents. Policy enforcement proxy for MCP with Human-in-the-Loop approval, DLP scanning, and audit logging.

agent-identity-protocol ai-agents ai-safety cursor-ide dlp golang human-in-the-loop llm mcp model-context-protocol policy-enforcement security zero-trust

Last synced: 29 May 2026

https://github.com/vmagamedov/security-framework

Step-by-step personal cybersecurity guide

2fa fido2 security yubikey

Last synced: 18 Jan 2026

https://github.com/owtf/http-request-translator

HTTP Request Translator (hrt) translates raw HTTP requests to different scripts (bash, python, etc.)

owasp owtf pentesting python security

Last synced: 17 Mar 2026

https://github.com/k--chow/solana-security

A compilation of solana security resources.

auditing ethereum security smart solana

Last synced: 11 Mar 2025

https://github.com/miathedev/kubeauth

A kubernetes multi type authentication provider using webhook token auth

auth authentication authorization identity k8s kubernetes ldap security

Last synced: 09 Apr 2025

https://github.com/valtteril/go-implant

A flexible cross-platform post-exploitation agent written in Go with basic functionalities

backdoor payload pentest post-exploitation rat redteam remote-access remote-admin-tool reverse-shell security

Last synced: 14 Jan 2026

https://github.com/sighupio/trivy-offline

Trivy offline builder. Fits perfectly in your CI System

cicd drone hacktoberfest quay sdlc security trivy

Last synced: 11 Mar 2025

https://github.com/sassman/srp6-rs

A safe implementation of the secure remote password authentication and key-exchange protocol (SRP and SRP6a)

authentication cryptography pki protocol rust secure-remote-password security srp srp-6a

Last synced: 19 Apr 2026

https://github.com/nccgroup/yocto-whitepaper-examples

Example code included in the "Improving Your Embedded Linux Security Posture with Yocto" whitepaper

linux openembedded security yocto

Last synced: 26 Apr 2025

https://github.com/3nock/ote-templates

Community curated list of templates for the OSINT template engine.

attack-surfaces bugbounty fingerprinting osint recon security templates

Last synced: 09 Feb 2026

https://github.com/vatshayan/final-year-project-steganography

Steganography is the technique of hiding secret data within an ordinary, non-secret, file or message in order to avoid detection; the secret data is then extracted at its destination.

btech-project capstone-project cipher college-project cryptography cryptography-project final-project final-projects final-year-project finalyearproject mtech-project project project-report research-paper-project security semester-project steganography university-project university-projects

Last synced: 28 Oct 2025

https://github.com/jakub-przepiora/ps-scan-prestashop-scanner

This tool serves as an initial version scanner specifically designed for PrestaShop, a popular e-commerce platform. The primary purpose of the scanner is to analyze PrestaShop instances for various aspects, such as module information, version details, and potential security vulnerabilities.

cve prestashop security security-tools

Last synced: 24 Oct 2025

https://github.com/rmbolger/pwnedpasscheck

Check passwords and hashes against the haveibeenpwned.com Pwned Passwords API using PowerShell

haveibeenpwned hibp infosec powershell powershell-module security

Last synced: 04 Jul 2025

https://github.com/bwireman/go-over

A tool to audit Erlang & Elixir dependencies, to make sure your ✨ gleam projects really sparkle!

audit beam cli dependencies dependency elixir erlang ghsa gleam javascript security security-audit security-tools tools vulnerable

Last synced: 28 Oct 2025

https://github.com/m3ssap0/spring-break_cve-2017-8046

This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).

cve-2017-8046 exploit security security-tools spring-break spring-data-rest vulnerability vulnerability-scanners

Last synced: 01 Mar 2026

https://github.com/akaunting/signed-url

Signed (unique) URL package for Laravel

laravel php security signed unique url

Last synced: 07 Jul 2025

https://github.com/nozaq/terraform-aws-secure-vpc

A terraform module to create a VPC with secure default configurations.

aws aws-auditing cis-benchmark devops hardening security security-hardening security-tools terraform vpc

Last synced: 06 May 2025

https://github.com/briandfoy/cpan-audit

Check CPAN modules for known security vulnerabilities

cve perl perl-module perl-tool security security-audit

Last synced: 13 Apr 2025

https://github.com/mindpatch/pmg

Extract parameters/paths from urls

bugbounty bugbounty-tool bughunting python regex security

Last synced: 12 Jul 2025