Showing 29 of 65 projects
A static analysis security scanner for Ruby web applications, supporting Rails, Sinatra, and Padrino frameworks.
A lightweight Python utility for running common security tests against GraphQL APIs, ideal for CI/CD checks.
A Python tool for automated scanning and detection of SSL/TLS vulnerabilities like Heartbleed, POODLE, and FREAK.
A Go-based tool to automatically scan networks for SSH servers with weak passwords and track credential vulnerabilities.
A best practices checker for Kubernetes clusters that analyzes resources and provides actionable feedback.
A fully open-source audit logs service with an embeddable UI, designed for easy deployment to your own Kubernetes cluster.
Automatically audit your Mac for basic security hygiene by checking common security fails and providing reminders.
A macOS app that automatically audits your Mac for basic security hygiene and reminds you to fix common security fails.
A multi-agent orchestration platform for Gemini CLI and Claude Code that coordinates 22 specialized AI agents for complex development tasks.
A secure, extensible command-line Android APK vulnerability analyzer written in Rust for automated security testing.
A Rust CLI tool to automate validation and invalidation workflows for API keys and secrets across 30+ providers.
A security inspection tool for managed Kubernetes clusters that identifies common misconfigurations via Docker container and web UI.
A bug hunting tool that scans websites for exposed .git repositories and dumps their contents for security analysis.
A self-hosted dashboard for analyzing AWS CloudTrail logs using ElasticSearch and Kibana.
A static analysis tool for Android applications that detects security vulnerabilities through inter-procedure and intra-procedure analysis.
A fast SNMP brute force, enumeration, and Cisco config downloader with password cracking capabilities.
A network security tool that detects the presence of a Responder LLMNR/NBT-NS poisoner in the network.
Visualizes AWS IAM and Organizations as a graph using Neo4j to identify security anomalies and privilege escalation paths.
Tools for vulnerability scanning and compliance auditing of Docker containers and images using OpenSCAP.
An open-source SIEM system built with Python Django for log management, risk assessment, and asset tracking.
Roslyn analyzers for detecting security vulnerabilities in .NET applications during development.
A Python tool for offline detection of Windows persistence mechanisms in forensic collections like KAPE dumps or mounted disk images.
Crack passwords of private key entries in Java Key Store (JKS) files using a GPU-accelerated hashcat implementation.
A customizable linter for validating Kubernetes resources against organization-defined standards.
Send encrypted PGP messages via a simple web link without signup, using public key servers.
A command-line tool to check email addresses and passwords against the Have I Been Pwned breach database.
Scans SPF and DMARC DNS records to identify vulnerabilities that could allow email spoofing attacks.
A tool for Exchange administrators to detect malicious client-side rules, VBScript forms, and custom homepages used in attacks.
A flexible Docker security audit tool using customizable audit profiles based on CIS benchmarks.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.