Showing 31 of 283 projects
A curated list of OpenID Connect providers, libraries, resources, and specifications for implementing modern authentication.
A curated list of OpenID Connect providers, libraries, resources, and specifications for implementing modern authentication.
A Python script that implements security testing attacks against AWS Cognito, including account oracle and privilege escalation.
An automated IAST fuzzer for discovering vulnerabilities in CakePHP web applications with minimal false positives.
A collection of writeups and solutions for Capture The Flag (CTF) cybersecurity challenges.
An open-source honeypot framework for NoSQL databases that simulates servers to detect and log attacks.
A standardized methodology for performing security assessments in robotics across physical, network, firmware, and application layers.
A collection of custom password cracking rules for Hashcat and John the Ripper to enhance brute-force attacks.
A honeypot that detects and logs exploitation attempts targeting the Log4Shell vulnerability (CVE-2021-44228).
A footprinting tool for scanning and fingerprinting robotic systems, including ROS, SROS, ROS2, and industrial routers.
An open dataset for learning-based temporal analysis of PE malware, containing over 130,000 Windows PE files with feature vectors and metadata.
A Python framework for generating synthetic log events without requiring actual infrastructure or actions.
A knowledge base documenting digital forensics artifacts to help investigators understand evidence sources and their forensic significance.
A neural network-based password cracking tool using character-level RNNs to learn and generate password guesses.
A tool that generates vulnerable web applications for security testing and education, supporting multiple attack modules.
A collaborative serverless framework for orchestrating geographically distributed assets to simulate offensive cyberspace operations.
A collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for educational purposes.
A free open-source Ruby on Rails scoring server for cyber Capture the Flag competitions with dynamic hints and web-based challenge management.
Apache 2-based honeypot and detection module for detecting and blocking the Struts CVE-2017-5638 exploit.
A Python script that monitors and alerts on indicators of compromise (IOCs) using Google Custom Search Engines and Safe Browsing APIs.
A Flask-based honeypot that mimics Outlook Web Access to detect and log authentication attempts.
A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.
An oh-my-zsh plugin providing aliases and functions for penetration testing and security auditing.
A Django-based web frontend for visualizing and analyzing data from the Dionaea low-interaction honeypot.
A honeynet system that deploys multiple honeypots, processes attack data with threat intelligence, and provides a web dashboard for analysis.
A security incident response card game that trains defenders through fictional scenarios and activity-based gameplay.
A collection of Go tools for performing exploitation and post-exploitation tasks over Tor with embedded Tor instances.
A Python-based low-interaction honeypot with sophisticated emulation for malware collection and analysis.
A distributed low-interaction honeypot with agent/master architecture for monitoring attacks across multiple protocols.
Docker container with a CLI toolkit for generating datasets of packed executables and training ML models for packing detection.
Open-source tools for creating realistic-behaving electric grid honeynets to detect and analyze cyber threats.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.