Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
A Collection of Hacks in IoT Space so that we can address them (hopefully).
🖖 GoCaptcha: A high-performance, interactive behavior captcha library for Go. Supporting click, slide, drag-drop, and rotation modes to secure your a...
Active Directory and Internal Pentest Cheatsheets
通用的Android inline hook库,支持thumb,arm32,arm64
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
An NFC research toolkit application for Android
Solo 1 firmware in C
A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables r...
Daily feed of bad IPs (with blacklist hit scores)
OWASP API Security Project
A fork and successor of the Sulley Fuzzing Framework
HTTP middleware for Go that facilitates some quick security wins.
针对SpringBoot的开源渗透框架,以及Spring相关高危漏洞利用工具
SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.
Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
A cryptographically verifiable code review system for the cargo (Rust) package manager.
The micro-VM for AI agents — light enough to embed on your laptop, elastic enough to power an agentic cloud.
XRay is a tool for recon, mapping and OSINT gathering from public networks.
Role and Attribute based Access Control for Node.js
A simple,high performance and secure live media server in pure Rust (RTMP[cluster]/RTSP/WebRTC[whip/whep]/HTTP-FLV/HLS).🦀
🔐🌐 Privacy-respecting web frontends for popular services
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
Run any Linux process in a secure, unprivileged sandbox using Landlock. Think firejail, but lightweight, user-friendly, and baked into the kernel.
Do you think you are safe using private browsing or incognito mode?. :smile: :imp: This will prove that you're wrong. Previously hosted at nothingpr...
A Vault swiss-army knife: A CLI tool to init, unseal and configure Vault (auth methods, secret engines).
A novel Android app store focused on security, privacy, and usability
👤 Identity and Access Management knowledge for cloud platforms
Easy to use alarm system integration for Home Assistant
🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
Binary Analysis Platform
iText for Java represents the next level of SDKs for developers that want to take advantage of the benefits PDF can bring. Equipped with a better docu...
Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.
This challenge is Inon Shkedy's 31 days API Security Tips.
Share your Immich photos and albums in a safe way without exposing your Immich instance to the public.
🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAut...
Advanced DNS filter/blocklists for privacy, security, and clean browsing.
OWASP Web Application Security Testing Checklist
A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications
A simple TLS proxy with mutual authentication for securing non-TLS services.
Since 2011, IPBan is the worlds most trusted, free security software to block hackers and botnets. With both Windows and Linux support, IPBan has your...
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writ...
Hacker tools on Go (Golang)
Authentication, authorization, traceability and auditability for SSH accesses.
A secure low code deception runtime framework, leveraging AI for System Virtualization.
🔐 oauth2 - A Ruby wrapper for the OAuth 2.0, & 2.1 Authorization Frameworks, including OpenID Connect (OIDC)
IAM Least Privilege Policy Generator
♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎
Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点
Venom - A Multi-hop Proxy for Penetration Testers
ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.