Otheractive
Awesome Security
Search 151 Security projects →151 projects32 categories
- 33%active
- 17%steady
- 28%slowing
- 22%dormant
Sourced fromsbilly/awesome-security
Projects 1–60 of 151, most starred first
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
PythonMIT Licenseactive
Command line and GUI tools for produce Java source code from Android Dex and Apk files.
JavaApache License 2.0active
A tool for developing and executing exploit code against a remote target machine. Other important sub-projects include the Opcode Database, shellcode archive and related research.
RubyOtheractive
A simple and comprehensive vulnerability scanner for containers and other artifacts, suitable for CI.
GoApache License 2.0active
Maigret collect a dossier on a person by username only, checking for accounts on a huge number of sites and gathering all the available information from web pages.
PythonMIT Licenseactive
Otheractive
awesome-* or *-awesome lists.
Rubyslowing
Identifies browser and hybrid mobile application users even when they purge data storage. Allows you to detect account takeovers, account sharing and repeated malicious activity.
TypeScriptMIT Licenseactive
A collection of awesome penetration testing resources, tools and other shiny things.
active
A tool for reverse engineering Android apk files.
JavaApache License 2.0active
Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.
MesonOtheractive
A curated list of awesome Hacking tutorials, tools and resources.
MIT Licenseslowing
Wazuh is a free and open source XDR platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. Great tool foor all kind of deployments, it includes SIEM capabitilies (indexing + searching + WUI).
C++Otheractive
docker pull owasp/zap2docker-stable - official OWASP ZAP
JavaApache License 2.0active
Amass performs DNS subdomain enumeration by scraping the largest number of disparate data sources, recursive brute forcing, crawling of web archives, permuting and altering names, reverse DNS sweeping and other techniques.
GoOtheractive
CrowdSec is a free, modern & collaborative behavior detection engine, coupled with a global IP reputation network. It stacks on Fail2Ban's philosophy but is IPV6 compatible and 60x faster (Go vs Python), uses Grok patterns to parse logs and YAML scenario to identify behaviors. CrowdSec is engineered for modern Cloud / Containers / VM based infrastructures (by decoupling detection and remediation). Once detected, you can remedy threats with various bouncers (firewall block, nginx http 403, Captchas, etc.) while the aggressive IPs can be sent to CrowdSec for curation before being shared among all users to further strengthen the community
GoMIT Licenseactive
A curated list of awesome malware analysis tools and resources.
Otherslowing
OpenSnitch is a GNU/Linux port of the Little Snitch application firewall
PythonGNU General Public License v3.0active
A curated list of movies every hacker & cyberpunk must watch.
ShellCreative Commons Zero v1.0 Universalslowing
A curated list of CTF frameworks, libraries, resources and software.
JavaScriptCreative Commons Zero v1.0 Universalslowing
jnv/lists on GitHub, opens in a new tab
11.4KstarsThe definitive list of (awesome) lists curated on GitHub.
Creative Commons Zero v1.0 Universalsteady
Fast subdomains enumeration tool for penetration testers
PythonGNU General Public License v2.0slowing
BunkerWeb is a full-featured open-source web server with ModeSecurity WAF, HTTPS with transparent Let's Encrypt renewal, automatic ban of strange behaviors based on HTTP codes, bot and bad IPs block, connection limits, state-of-the-art security presets, Web UI and much more.
PythonGNU Affero General Public License v3.0active
A curated list of threat intelligence resources.
Apache License 2.0active
The canonical awesome honeypot list.
PythonArtistic License 2.0active
A curated list of privacy-respecting software and services.
AstroCreative Commons Zero v1.0 Universalactive
A collection of android security related resources. A lot of work is happening in academia and industry on tools to perform dynamic analysis, static analysis and reverse engineering of android apps.
MakefileApache License 2.0active
A curated list of resources for incident response.
Apache License 2.0active
Open-source VPN server and egress firewall for Linux built on WireGuard that makes it simple to manage secure remote access to your company’s private networks. Firezone is easy to set up (all dependencies are bundled thanks to Chef Omnibus), secure, performant, and self hostable.
ElixirApache License 2.0active
Store AWS credentials in the OSX Keychain or an encrypted file
GoMIT Licensesteady
A static analysis tool for infrastucture as code (Terraform).
PythonApache License 2.0active
Python based memory extraction and analysis framework.
PythonGNU General Public License v2.0slowingarchived
A collection of interesting, funny, and depressing search queries to plug into Shodan.io.
Creative Commons Zero v1.0 Universalslowing
This list is for anyone wishing to learn about web application security but do not have a starting point.
MIT Licenseactive
A semi automatic pen testing tool for mapping/pen-testing networks. Simulates a human attacker.
PythonGNU General Public License v3.0slowing
Safely store secrets in a VCS repo using GPG
GoMIT Licensesteadyarchived
Fleet is the lightweight, programmable telemetry platform for servers and workstations. Get comprehensive, customizable data from all your devices and operating systems.
GoOtheractive
A collection of awesome security hardening guides, best practices, checklists, benchmarks, tools and other resources.
steady
Recon-ng is a full-featured Web Reconnaissance framework written in Python. Recon-ng has a look and feel similar to the Metasploit Framework.
PythonGNU General Public License v3.0slowing
The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
Pythonslowing
Dshell is a network forensic analysis framework. Enables rapid development of plugins to support the dissection of network packet captures.
PythonOtherslowing
The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms, as well as a pluggable authentication module (PAM). One-time passcodes are generated using open standards developed by the Initiative for Open Authentication (OATH) (which is unrelated to OAuth). These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (TOTP) algorithm specified in RFC 6238. Tutorials: How to set up two-factor authentication for SSH login on Linux
JavaApache License 2.0dormantarchived
Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
TypeScriptApache License 2.0active
GRR Rapid Response is an incident response framework focused on remote live forensics.
PythonApache License 2.0steady
NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX, NAXSI means Nginx Anti Xss & Sql Injection.
CGNU General Public License v3.0slowingarchived
A curated list of awesome threat detection and hunting resources.
steady
A curated list of hacking environments where you can train your cyber skills legally and safely.
MIT Licenseslowing
Axiom is a dynamic infrastructure framework to efficiently work with multi-cloud environments, build and deploy repeatable infrastructure focussed on offensive and defensive security.
ShellMIT Licenseslowing
Collection of the cheat sheets useful for pentesting
slowingarchived
A curated list of awesome security talks, organized by year and then conference.
steady
Simple Indicators of Compromise and Incident Response Scanner
PythonGNU General Public License v3.0steady
This project was created to publish the best practices for segmentation of the corporate network of any company. In general, the schemes in this project are suitable for any company.
Apache License 2.0steady
A collection of tools developed by other researchers in the Computer Science area to process network traces.
Creative Commons Zero v1.0 Universalsteady
Find secrets and passwords in container images and file systems.
GoMIT Licensesteady
An open source RASP solution actively maintained by Baidu Inc. With context-aware detection algorithm the project achieved nearly no false positives. And less than 3% performance reduction is observed under heavy server load.
C++Apache License 2.0steady
Scan code for security risks and vulnerabilities leading to sensitive data exposures.
GoOtheractive
Scans IaC projects for security vulnerabilities, compliance issues, and infrastructure misconfiguration. Currently working with Terraform projects, Kubernetes manifests, Dockerfiles, AWS CloudFormation Templates, and Ansible playbooks.
Open Policy AgentApache License 2.0active
Store secrets using AWS KMS and SSM Parameter Store
GoMIT Licenseactive
Fibratus is a tool for exploration and tracing of the Windows kernel. It is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very simple CLI which encapsulates the machinery to start the kernel event stream collector, set kernel event filters or run the lightweight Python modules called filaments.
GoOtheractive