Showing 36 of 355 projects
A centralized repository summarizing practical and proposed defenses against prompt injection attacks on large language models.
Scirius is a web application for Suricata ruleset management and threat hunting.
Route-level file upload security for Node.js, scanning files for malware, spoofing, and risky archives before storage.
A Ruby-based command-line tool for analyzing password dumps to generate statistics and insights for security reports.
A tool to gather and enrich threat intelligence indicators from publicly available sources into a structured CSV format.
A Python tool for automated scanning and detection of SSL/TLS vulnerabilities like Heartbleed, POODLE, and FREAK.
An open-source framework for detecting command and control communication through network traffic analysis using Zeek logs.
A curated list of resources for understanding, detecting, and mitigating prompt injection attacks against machine learning models.
A customizable security middleware for Apollo GraphQL, Yoga, and Envelop GraphQL servers.
A Python library and CLI for extracting and refanging defanged Indicators of Compromise (IOCs) from text.
A collection of public exploits targeting malware infrastructure for security research and analysis.
A forensic tool for exploring offline Docker filesystems to analyze compromised containers.
Default playbooks and custom functions for Splunk SOAR (formerly Phantom) security orchestration and automation platform.
A collection of CTF challenge write-ups that demonstrate solutions using the pwntools exploit development library.
An educational chatbot designed to demonstrate and experiment with prompt injection attacks against LLM ReAct agents.
A high-performance word generator for password cracking with per-position configurable character sets.
A Volatility plugin that extracts configuration data and decoded strings from known malware families in memory images.
A Windows Batch and Unix Bash script suite for comprehensive host forensic data collection during incident response.
An open-source Python framework for creating honeypots and honeynets to detect and analyze cyber attacks.
A web application honeypot sensor that clones websites to attract and analyze malicious attacks.
A powerful, easily deployable network traffic analysis tool suite for PCAP files, Zeek logs, and Suricata alerts.
A low to medium interaction honeypot written in Python, designed for easy deployment and extensibility.
A collection of hashcat and John the Ripper rules for password cracking, optimized for common password generation patterns.
A collection of publicly shared Indicators of Compromise (IOCs) from FireEye for threat intelligence and security research.
A collection of built-in detection rules and policies for Panther, a modern SIEM, enabling security monitoring as code.
A lightweight, fast, and scalable CTF (Capture The Flag) competition engine written in PHP.
A lightweight investigation notebook for security analysts to document and track threat intelligence.
A collection of prescriptive recipes for preparing and applying countermeasures against cyber threats and attacks.
A browser extension that streamlines security investigations by providing quick lookups for IPs, domains, hashes, and other indicators.
A modified fork of Cuckoo Sandbox with enhanced malware analysis capabilities, improved stability, and additional features.
A Python sandbox that automatically collects, analyzes, and reports runtime indicators of Linux malware through static, dynamic, and memory analysis.
Discover internet-wide misconfigurations in services like Elasticsearch, databases, and web servers using high-speed scanning tools.
A scalable, pluggable, and distributed queue and resource system for password cracking and other compute-intensive tasks.
A collection of native security controls for major cloud platforms mapped to MITRE ATT&CK techniques to enable threat-informed defense decisions.
A collaborative malware analysis framework for storing samples, automating analysis, and sharing insights via IDA Pro integration.
A tool for automatic analysis of malware behavior using machine learning to identify, cluster, and classify malicious software.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.