Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks.
Minimal TOTP generator in 20 lines of Python
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
🔒 A collection of cheatsheets for various infosec tools and topics.
💥 A collection of all documents leaked by former NSA contractor and whistleblower Edward Snowden.
Enhance the security and privacy of your Windows 10 and Windows 11 deployments with our fully optimized, hardened, and debloated script. Adhere to ind...
Home Assistant integration to manage Eufy Security devices as cameras, home base stations, doorbells, motion and contact sensors.
Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Template...
This is just an semi-automated fully working, no-bs, non-metasploit version of the public exploit code for MS17-010
Superseded by https://github.com/aquasecurity/trivy-operator
TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!
A GitHub Action for authenticating to Google Cloud.
Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++.
AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.
USBGuard is a software framework for implementing USB device authorization policies (what kind of USB devices are authorized) as well as method of use...
A Toolbox for Adversarial Robustness Research
:key: Community-driven Rails Security Checklist (see our GitHub Issues for the newest checks that aren't yet in the README)
A utility to safely generate malicious network traffic patterns and evaluate controls.
🏆Open Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)
Cloud-native authorization for modern applications and APIs
Modern camera app focused on privacy and security with QR & barcode scanning.
python安全和代码审计相关资料收集 resource collection of python security and code review
Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
Useful Google Dorks for WebSecurity and Bug Bounty
cwe_checker finds vulnerable patterns in binary executables
Penetration Testing Platform
Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them
An authorization library that supports access control models like ACL, RBAC, ABAC in PHP .
An Active Defense and EDR software to empower Blue Teams
Full Toolkit for Next-Level Domain Analysis
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
Simple Golang HTTPS/TLS Examples
Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.
Monkey365 is an open-source security assessment tool for Microsoft 365, Azure, and Microsoft Entra ID. It helps security professionals identify miscon...
Environment variables meet macOS Keychain and gnome-keyring <3
AD Security Intrusion Detection System
A Slack bot for GitHub organization management -- and other things too
FIDO2 Conformant WebAuthn and Passkey backend library for golang
PacBot (Policy as Code Bot)
The repo contains a series of challenges for learning Frida for Android Exploitation.
Linting tool for CloudFormation templates
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dyn...
Most usable tools for iOS penetration testing
Advanced Honeypot framework.
secator - the pentester's swiss knife
Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain...
The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides...
A Tox-based instant messaging and video chat client.