Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
A framework agnostic authentication & authorization system.
LLM Prompt Injection Detector
ICS/SCADA honeypot
Obtain GraphQL API schema even if the introspection is disabled
OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-u...
A default credential scanner.
Attack surface mapping
GlobaLeaks is a free and open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.
HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。
A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.
Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitiv...
白阁文库是白泽Sec安全团队维护的一个漏洞POC和EXP公开项目
Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more
The SOC Analysts all-in-one CLI tool to automate and speed up workflow.
Secure-by-default HTTP servers in Go.
LibreSSL Portable itself. This includes the build scaffold and compatibility layer that builds portable LibreSSL from the OpenBSD source code. Pull re...
Database security suite. Database proxy with field-level encryption, search through encrypted data, SQL injections prevention, intrusion detection, ho...
Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.
Secure Vault for Customer PII/PHI/PCI/KYC Records
A curated list of awesome Ethereum security references
Awesome Vulnerable Applications
Security risk analysis for Kubernetes resources
One Time Password (HOTP/TOTP) library for Node.js, Deno, Bun and browsers.
IBM Fully Homomorphic Encryption Toolkit For Linux. This toolkit is a Linux based Docker container that demonstrates computing on encrypted data witho...
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Build...
A php.ini scanner for best security practices
SSH-MITM - ssh audits made simple
Username tools for penetration testing
Community-driven baseline to accelerate Intune adoption and learning.
Infra provides authentication and access management to servers and Kubernetes clusters.
Firmware Analysis and Comparison Tool
Vulnerable app with examples showing how to not use secrets
This repository has a new home: https://git.synz.io/Synzvato/decentraleyes
OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure
Qtap: An eBPF agent that captures pre-encrypted network traffic, providing rich context about egress connections and their originating processes.
Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.
BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.
🔐 Run frida-server on boot with Magisk, always up-to-date
Perform a MitM attack and extract clear text credentials from RDP connections
Privacy-first PDF utility (Zero-Server Architecture). Merge, split, compress, and edit PDFs 100% locally on your device. No uploads, no servers, no tr...
UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the...
A libre cross-platform disassembler.
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting,...
High Performance GraphQL Runtime
LLM powered fuzzing via OSS-Fuzz.
FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sen...
傻瓜式漏洞PoC测试框架
保护你的浏览器指纹 | Protect Your Browser Fingerprints | Chrome, Edge, Firefox | 扩展 / Extension
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
🔐 Out of the box stateless openvpn-server docker image which starts in less than 2 seconds