Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
Cross-platform desktop GUI app to clean image metadata
Keystone assembler framework: Core (Arm, Arm64, Hexagon, Mips, PowerPC, Sparc, SystemZ & X86) + bindings
🕵️ OSINT Tools for gathering information and actions forensics 🕵️
Extensible security first OAuth 2.0 and OpenID Connect SDK for Go.
A fork of AFL for fuzzing Windows binaries
FISCO BCOS(发音为/ˈfɪskl bi:ˈkɒz/)是一个稳定、高效、安全的许可区块链平台,已被广泛应用于现实的行业应用。截至目前,已拥有5000多家企事业单位,400多个...
You don't have the time to watch all the WWDC session videos yourself? No problem me and many contributors extracted the gist for you 🥳
Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF, AppA...
Captcha for Laravel 5+
一款部署于云端或本地的隧道代理池中间件,可将静态代理IP灵活运用成隧道IP,提供固定请求地址,一次部署终身使用
Phishing Campaign Toolkit
nodejsscan is a static security code scanner for Node.js applications.
🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository s...
JWT brute force cracker written in C
Automating situational awareness for cloud penetration tests.
🕵️♂️ TUI for sniffing network traffic using eBPF on Linux
🚀 Caido releases, wiki and roadmap
lightweight, dependency-free bash script for security, performance auditing and infrastructure monitoring of Linux servers.
红队作战中比较常遇到的一些重点系统漏洞整理。
Security engine for Java (authentication, authorization, multi frameworks): OpenID Connect, SAML2, CAS, OAuth, LDAP, JWT...
Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+...
Security sensor for realtime threat detection and protection
Copy/paste anything over the network.
Semi-automatic OSINT framework and package manager
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
Powerful framework for rogue access point attack.
兜哥出品 <一本开源的NLP入门书籍>
DEPRECATED, bettercap developement moved here: https://github.com/bettercap/bettercap
A collection of smart contract vulnerabilities along with prevention methods
A very small, very simple, yet very secure encryption tool.
Provides a tight integration of the Security component into the Symfony full-stack framework
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata al...
Creepy device and browser fingerprinting
🛡️ Awesome Cloud Security Resources ⚔️
Single Sign-On for Your Self-Hosted Universe
U2F USB token optimized for physical security, affordability, and style
A p2p, secure file storage, social network and application protocol
Security Scanner for Agent Skills
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
A curated list of awesome embedded and IoT security resources.
A Collection of Hacks in IoT Space so that we can address them (hopefully).
Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
DockFlare: Automate Cloudflare Tunnels with Docker Labels
🖖 GoCaptcha: A high-performance, interactive behavior captcha library for Go. Supporting click, slide, drag-drop, and rotation modes to secure your a...
Solo 1 firmware in C
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
通用的Android inline hook库,支持thumb,arm32,arm64
Active Directory and Internal Pentest Cheatsheets