Showing 36 of 359 projects
A language server implementing the Language Server Protocol for Suricata signatures, providing syntax checking, hints, and auto-completion.
Automated script to install and configure Dionaea and Kippo honeypots as system services on Ubuntu.
Analyzes web traffic via Squid proxy to detect command and control servers and malicious sites using Spamhaus data.
Simplified certificate authority and device certificate manager for strongSwan VPN, supporting client/server, host-to-host, and site-to-site configurations.
A command-line tool for fuzzing network protocols by automating packet modifications to test firewall and IDS evasion.
A lightweight full-packet network traffic recorder and buffering tool for commodity hardware.
An SNMP proxy forwarder with built-in message routing, protocol translation, and split client/server architecture for secure deployments.
An RDP honeypot that captures attack telemetry by simulating Windows RDP sessions with virtual machines.
A Python library for performing enhanced Multi-Traceroute (MTR) with scapy and generating SVG visualizations.
Automatically manages iptables rules to secure DigitalOcean droplets by allowing traffic only from other droplets.
A Django-based web frontend for visualizing and analyzing data from the Dionaea low-interaction honeypot.
A CLI tool that creates a DigitalOcean Droplet and sets up transparent network proxying via sshuttle.
An open-source book providing SOC analysts and threat hunters with practical guidance on using Suricata for network security monitoring.
A honeypot platform for monitoring and analyzing UDP-based DDoS amplification attacks via DNS, NTP, SSDP, Chargen, and generic UDP services.
A distributed low-interaction honeypot with agent/master architecture for monitoring attacks across multiple protocols.
A Python-based low-interaction honeypot with sophisticated emulation for malware collection and analysis.
A proof-of-concept tool to externally detect Kippo SSH honeypot instances.
A honeypot that mimics Drupal CMS to detect and log malicious scanning and attack attempts.
A fast, extensible event router for processing Suricata's JSON EVE output, designed for high-throughput network security monitoring.
An ICAP server that scans web content and URLs using YARA rules for security filtering.
A low-interaction honeypot that emulates Cisco ASA devices to detect exploitation attempts targeting CVE-2018-0101.
A Node.js library for programmatically creating SSH tunnels with flexible local and remote port forwarding.
A Python-based NTP honeypot that logs NTP scan attempts and DDoS reconnaissance into Redis for security monitoring.
A Python-based web server honeypot and service imitation builder for faking HTTP services and recording requests.
An Intrusion Prevention System (IPS) for SSH that blocks brute force attacks using iptables and optional nmap/dig probes.
A security analysis tool that automatically detects misconfigurations and vulnerabilities in MQTT brokers.
A DNS honeypot that logs requests to SQLite/JSON and mimics an open resolver with configurable sinkhole behavior.
A high-interaction honeypot that emulates the SMB protocol to detect and analyze network attacks.
A honeypot server written in Go that logs attacker interactions to a database.
Bash and Python scripts that listen on unused ports and automatically blacklist IPs that connect to them.
A secure Lisp reader wrapper that protects against internbombing, excessive input, and macro characters when reading from untrusted sources.
A multi-threaded proof-of-concept tool for conducting denial-of-service stress tests over the Tor network.
A honeypot that isolates each attacker connection in a separate LXC container for monitoring and analysis.
IPv6 attack detector that identifies link-local security threats from tools like THC-IPv6 and Nmap.
A Kubernetes API honeypot with multi-protocol emulation and active defense capabilities for detecting malicious infrastructure attacks.
A decentralized AI security mesh that provides collective defense, where threat detection on any node protects all nodes within 30 seconds.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.