Showing 36 of 355 projects
A centralized repository summarizing practical and proposed defenses against prompt injection attacks on large language models.
Scirius is a web application for Suricata ruleset management and threat hunting.
A Ruby-based command-line tool for analyzing password dumps to generate statistics and insights for security reports.
Route-level file upload security for Node.js, scanning files for malware, spoofing, and risky archives before storage.
A tool to gather and enrich threat intelligence indicators from publicly available sources into a structured CSV format.
A Python tool for automated scanning and detection of SSL/TLS vulnerabilities like Heartbleed, POODLE, and FREAK.
An open-source framework for detecting command and control communication through network traffic analysis using Zeek logs.
A customizable security middleware for Apollo GraphQL, Yoga, and Envelop GraphQL servers.
A Python library and CLI for extracting and refanging defanged Indicators of Compromise (IOCs) from text.
A curated list of resources for understanding, detecting, and mitigating prompt injection attacks against machine learning models.
A collection of public exploits targeting malware infrastructure for security research and analysis.
A forensic tool for exploring offline Docker filesystems to analyze compromised containers.
Default playbooks and custom functions for Splunk SOAR (formerly Phantom) security orchestration and automation platform.
A collection of CTF challenge write-ups that demonstrate solutions using the pwntools exploit development library.
A high-performance word generator for password cracking with per-position configurable character sets.
A Volatility plugin that extracts configuration data and decoded strings from known malware families in memory images.
An educational chatbot designed to demonstrate and experiment with prompt injection attacks against LLM ReAct agents.
A Windows Batch and Unix Bash script suite for comprehensive host forensic data collection during incident response.
An open-source Python framework for creating honeypots and honeynets to detect and analyze cyber attacks.
A web application honeypot sensor that clones websites to attract and analyze malicious attacks.
A low to medium interaction honeypot written in Python, designed for easy deployment and extensibility.
A powerful, easily deployable network traffic analysis tool suite for PCAP files, Zeek logs, and Suricata alerts.
A collection of hashcat and John the Ripper rules for password cracking, optimized for common password generation patterns.
A collection of publicly shared Indicators of Compromise (IOCs) from FireEye for threat intelligence and security research.
A collection of built-in detection rules and policies for Panther, a modern SIEM, enabling security monitoring as code.
A lightweight, fast, and scalable CTF (Capture The Flag) competition engine written in PHP.
A lightweight investigation notebook for security analysts to document and track threat intelligence.
A collection of prescriptive recipes for preparing and applying countermeasures against cyber threats and attacks.
A browser extension that streamlines security investigations by providing quick lookups for IPs, domains, hashes, and other indicators.
A modified fork of Cuckoo Sandbox with enhanced malware analysis capabilities, improved stability, and additional features.
A Python sandbox that automatically collects, analyzes, and reports runtime indicators of Linux malware through static, dynamic, and memory analysis.
Discover internet-wide misconfigurations in services like Elasticsearch, databases, and web servers using high-speed scanning tools.
A scalable, pluggable, and distributed queue and resource system for password cracking and other compute-intensive tasks.
A collection of native security controls for major cloud platforms mapped to MITRE ATT&CK techniques to enable threat-informed defense decisions.
A collaborative malware analysis framework for storing samples, automating analysis, and sharing insights via IDA Pro integration.
A tool for automatic analysis of malware behavior using machine learning to identify, cluster, and classify malicious software.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.