Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
SSH-MITM - ssh audits made simple
One Time Password (HOTP/TOTP) library for Node.js, Deno, Bun and browsers.
铜锁/Tongsuo is a Modern Cryptographic Primitives and Protocols Library
High Performance GraphQL Runtime
🔐 Out of the box stateless openvpn-server docker image which starts in less than 2 seconds
Qtap: An eBPF agent that captures pre-encrypted network traffic, providing rich context about egress connections and their originating processes.
Obtain GraphQL API schema even if the introspection is disabled
Vulnerable app with examples showing how to not use secrets
Symfony Security Component - Guard
📗 How to write cross-platform Node.js code
FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sen...
Collection of the most common vulnerabilities found in iOS applications
Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting,...
Advbox is a toolbox to generate adversarial examples that fool neural networks in PaddlePaddle、PyTorch、Caffe2、MxNet、Keras、TensorFlow and Advbox c...
Secure Vault for Customer PII/PHI/PCI/KYC Records
Awesome Security lists for SOC/CERT/CTI
Minimal TOTP generator in 20 lines of Python
A free book about developing secure and robust systems software.
The iOS Security Testing Framework
🔒 A collection of cheatsheets for various infosec tools and topics.
Awesome Vulnerable Applications
LLM powered fuzzing via OSS-Fuzz.
Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++.
Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Template...
Superseded by https://github.com/aquasecurity/trivy-operator
🔐 Run frida-server on boot with Magisk, always up-to-date
AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project
:key: Community-driven Rails Security Checklist (see our GitHub Issues for the newest checks that aren't yet in the README)
A Toolbox for Adversarial Robustness Research
A utility to safely generate malicious network traffic patterns and evaluate controls.
This is just an semi-automated fully working, no-bs, non-metasploit version of the public exploit code for MS17-010
Username tools for penetration testing
Enhance the security and privacy of your Windows 10 and Windows 11 deployments with our fully optimized, hardened, and debloated script. Adhere to ind...
python安全和代码审计相关资料收集 resource collection of python security and code review
Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more
Penetration Testing Platform
Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks.
cwe_checker finds vulnerable patterns in binary executables
🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
Simple Golang HTTPS/TLS Examples
An authorization library that supports access control models like ACL, RBAC, ABAC in PHP .
USBGuard is a software framework for implementing USB device authorization policies (what kind of USB devices are authorized) as well as method of use...
💥 A collection of all documents leaked by former NSA contractor and whistleblower Edward Snowden.
Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.
TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!
AD Security Intrusion Detection System
Cloud-native authorization for modern applications and APIs
An Active Defense and EDR software to empower Blue Teams