Showing 36 of 107 projects
A Rust library for fuzzing Rust code with AFLplusplus to find security and stability issues.
A grammar-based DOM fuzzer that generates HTML, CSS, and JavaScript test cases to find security vulnerabilities in web browsers.
An automated framework for monitoring and tampering with system API calls of native macOS, iOS, and Android apps using Frida.
A comprehensive password cracking rule combining multiple sources for improved hashcat performance.
A free, cross-platform, single-file fake protocol server simulator that can start or stop multiple network services.
Statistical password cracking rules for Hashcat based on industry patterns and frequency analysis.
A lightweight, security-focused BDD test framework for Terraform that enables compliance and negative testing for infrastructure-as-code.
A lightweight utility to generate malicious network traffic patterns for evaluating security controls and network visibility.
Wordlists for statistically likely usernames, optimized for horizontal password attacks and security testing.
An AI-powered tool that analyzes source code to discover every endpoint, exposing shadow APIs and mapping the complete attack surface for security testing.
A shell script that creates a transparent proxy through the Tor network for Kali Linux, routing all system traffic anonymously.
An information security preparedness tool for adversarial simulation using Redis/Celery, Python, and Vagrant.
A framework of Python scripts for blue teams to test detection capabilities against malicious tradecraft modeled after MITRE ATT&CK.
An open-source AI testing agent that automates UI, API, security, accessibility, and visual validations using Gherkin without code.
A massive 82 billion entry wordlist compiled from multiple password dictionaries for security testing.
A ruggedization framework for security testing that is usable by developers, operations, and security teams.
A curated list of awesome fuzzing resources, tools, and academic papers for software security testing.
A mutation-based coverage-guided fuzzer that increases branch coverage by solving path constraints without symbolic execution.
A friendly automotive security exploration tool for the CAN bus, enabling zero-knowledge discovery of services and vulnerabilities.
A vulnerable Android CTF application demonstrating real-world security vulnerabilities and exploitation techniques.
A comprehensive mobile application reverse engineering and analysis framework for security testing against OWASP mobile threats.
A malicious DNS server for executing DNS rebinding attacks dynamically via domain name requests.
A serverless distributed hash-cracking platform built on AWS, offering pay-as-you-go GPU power with an intuitive UI.
An advanced keyboard-walk generator for password cracking, configurable with base characters, keymaps, and routes.
A collection of PowerShell scripts for security testing, penetration testing, and general system administration tasks.
A command-line tool for security testing and offensive operations against Jenkins CI/CD servers.
A TensorFlow-based image recognition system for captchas that works without image segmentation.
A fast and flexible HTTP fuzzer for content discovery, credential bruteforcing, and security testing.
An automated API security testing tool that generates and runs fuzzing attacks based on an OpenAPI/Swagger specification.
A framework for exploiting DNS rebinding vulnerabilities to bypass Same-Origin Policy and attack internal networks from browsers.
A scriptable network authentication cracker for custom services, using Lua scripts to test credentials.
A Python tool that automates DDoS attacks through the Tor network for security testing and education.
A Rust-based manually-guided fuzzing framework for Solana programs, processing up to 12,000 transactions per second.
A Ruby library for reading, writing, and manipulating network packets at a mid-level.
A fuzzer for Linux kernel drivers that combines interface recovery via LLVM analysis with a fuzzing engine to find security vulnerabilities.
A kernel fuzzer that specifically targets race condition bugs in operating system kernels.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.