Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and r...
A collection of practical security-focused guides and checklists for smart contract development
Custom & better AppArmor profile generator for Docker containers.
🔒 Enterprise-grade API gateway that helps you monitor and impose cost or rate limits per API key. Get fine-grained access control and monitoring per...
Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. Hundreds of rules.
An IIS short filename enumeration tool
Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of a...
🔒 Anti DDOS | Bash Script Project 🔒
Package gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services 🔒
FuzzBench - Fuzzer benchmarking as a service.
Software Supply Chain Transparency Log
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
A modular vulnerability scanner with automatic report generation capabilities.
AI Captcha Bypass
Scan the devices connected to your WIFI / LAN and alert you the connection of unknown devices. It also warns if a "always connected" device disconnect...
网络安全学习资料,欢迎补充
JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield,...
Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational S...
Provides a complete security system for your web application
pinact is a CLI to edit GitHub Workflow and Composite action files and pin versions of Actions and Reusable Workflows. pinact can also update their ve...
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could...
⭐ ⭐ Use ML to classify flows and packets as benign or malicious. ⭐ ⭐
Easily configure macOS security settings from the terminal.
Program to reverse Docker images into Dockerfiles
SSHamble: Unexpected Exposures in SSH
PHP library for Two Factor Authentication (TFA / 2FA)
Tracking history of USB events on GNU/Linux
OSINT from your favorite services in a friendly terminal user interface - integrations for Virustotal, Shodan, and Censys
PHP security vulnerabilities checker
Simple HS256, HS384 & HS512 JWT token brute force cracker.
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plu...
OpenVPN 3 is a C++ class library that implements the functionality of an OpenVPN client, and is protocol-compatible with the OpenVPN 2.x branch.
码小六 - GitHub 代码泄露监控系统
Security advisory database for Rust crates published through crates.io
Wazuh - Docker containers
Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.
Verify apps easily.
Lightweight Certificate Transparency Log Monitor
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
A Huge Learning Resources with Labs For Offensive Security Players
vet is a command-line tool that acts as a safety net for the risky curl | bash pattern. It lets you inspect, diff against previous versions, and lint...
Vulnerability Labs for security analysis
CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys
Browser's XSS Filter Bypass Cheat Sheet
SSH-based "VPN for poors"
ConardLi blogs
A pure Python HTML5 parser that just works. No C extensions to compile. No system dependencies to install. No complex API to learn.
AWS Least Privilege for Distributed, High-Velocity Deployment
An information security preparedness tool to do adversarial simulation.