Showing 36 of 39 projects
A comprehensive, evolving guide to hardening a Linux server with practical steps and security best practices.
SlimToolkit minifies and secures container images by up to 30x without requiring changes to your Dockerfile or workflow.
A comprehensive cheat sheet for Docker commands, best practices, and security tips.
A security auditing and hardening tool for UNIX-based systems, performing in-depth scans and compliance testing.
An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.
An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.
A collection of Nginx configuration files to improve server performance, security, and resource delivery.
A low-level unprivileged sandboxing tool for Linux that creates container-like environments without requiring root privileges.
A curated collection of security hardening guides, best practices, checklists, benchmarks, and tools for various systems and services.
An Ansible collection providing battle-tested security hardening for Linux, SSH, nginx, and MySQL.
A transpiler that migrates C99-compliant code to unsafe Rust, preserving functionality and enabling incremental refactoring.
A lightweight Linux process isolation tool using namespaces, cgroups, rlimits, and seccomp-bpf syscall filters for enhanced security.
A Ruby gem for automatically applying security headers with safe defaults to protect web applications from common vulnerabilities.
A Windows security tool that reduces the attack surface by disabling risky features in Windows, Office, Adobe Reader, and LibreOffice.
A production-ready auditd configuration for Linux security monitoring that works out-of-the-box across major distributions.
A BloodHoundAD report engine that transforms Neo4J graph queries into actionable security reports for blue and purple teams.
A custom AppArmor profile generator for Docker containers that simplifies security configuration.
A custom AppArmor profile generator for Docker containers that simplifies container security.
A Terraform module to configure AWS accounts with a secure baseline aligned to CIS AWS Foundations and AWS Foundational Security Best Practices.
A CI/CD security agent that monitors GitHub Actions runners for threats like network egress, file integrity, and process activity.
A command-line tool to securely configure macOS security and privacy settings with a single command.
A command-line tool to securely configure macOS security and privacy settings with a single command.
A script that generates VirtualBox templates to harden Windows VMs against malware detection.
A practical guide to configuring secure online communication and services using cryptography best practices.
PowerShell module to check Windows binaries for security features like ASLR, DEP, SafeSEH, and Authenticode.
A collection of Nix packages and NixOS modules for securely deploying full-featured Bitcoin and Lightning nodes.
A collection of production-ready Nginx configuration snippets, templates, and best practices for common web server setups.
An InSpec compliance profile that automates security testing for Docker daemon and containers against CIS benchmarks.
A script to quickly harden UNIX/Linux system permissions and ownership for security compliance and standardization.
A curated list of resources for detecting threats and defending Kubernetes systems.
A Rails application template preloaded with best practices for TDD, security, deployment, and developer productivity.
An OCI hook that traces container syscalls using eBPF to generate tailored seccomp security profiles.
An open-source blue team tool that protects Linux and Windows operating systems through multiple security methods.
An Ansible role that automates the deployment and management of Tor relays with security features like offline master keys and Prometheus monitoring.
Tools for vulnerability scanning and compliance auditing of Docker containers and images using OpenSCAP.
An OCI-compatible container engine designed specifically for running Linux containers on High Performance Computing (HPC) environments.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.