Showing 35 of 143 projects
An Android port of the Radamsa fuzzer for security testing on Android devices.
A framework and tool for automated black-box testing of RESTful APIs using OpenAPI specifications.
A multi-transaction differential fuzzer for finding consensus bugs in Ethereum clients.
Official Node.js client library for programmatically accessing the OWASP Zed Attack Proxy (ZAP) API.
A methodology and toolset for creating reusable attack maps to integrate security threat modeling into software development workflows.
A hybrid data-driven REST API fuzzer that combines sequence generation, request quality improvement, and parameter error detection.
A blazingly fast CLI hash generator supporting 60+ hash functions, encoding, and decoding operations.
An action-guided kernel fuzzing framework that synthesizes fuzzer programs based on triggered actions and their temporal relationships.
Generates exhaustive password mutations from wordlists, websites, or stdin for security testing and password cracking.
A file format fuzzer for Android that pushes test files to emulators and monitors apps for buffer overflows.
A hybrid stateful fuzzing framework for USB gadget stacks in the Linux kernel.
A coroutines-driven Low & Slow traffic generator for penetration testing, written in Rust.
A red team automation tool that simulates advanced attacker behavior in AWS environments for security testing.
A browser fuzzer that synthesizes test cases using memory-level API modification-reference relations to improve relevance.
An end-to-end fuzzing framework that brings coverage-guided fuzzing to kernel concurrency testing to detect data races.
A fuzzing tool for detecting Spectre vulnerabilities in software through dynamic analysis.
A collection of Danish wordlists for password cracking and security testing.
A Python script that inspects multi-byte character sets to find characters with user-defined properties for security testing.
A fuzzing tool for ROS2 nodes that tests topics and services with pseudorandom data to uncover bugs and vulnerabilities.
Adversarial tool that alters packed executables to evade static packing detection by malware analysis tools.
A GitHub Action for running Go 1.18+ built-in fuzz testing in CI/CD workflows.
A blockchain consensus protocol fuzzing framework that detects memory-related and logic bugs by modeling node states.
A fuzzing framework for automatically detecting and exploiting template escape bugs in template engines.
A Symfony bundle that integrates the Visithor library for testing application routes with specific HTTP codes.
A Go-based load testing tool specifically designed for SSH servers.
A Robot Framework toolkit for testing Solidity smart contracts, deploying them across EVM chains, and building blockchain monitoring bots.
A friendly automotive security exploration tool for CAN bus and ECU vulnerability research.
An experimental framework for building structure-aware, library API fuzzers using lifetime-aware dataflow graphs.
A comprehensive Albanian wordlist combining names, surnames, literature, and public sources for security testing.
Generates wordlists of Danish phone numbers filtered by area code and line type for security testing.
GitHub Action that runs the dlint security linter on Python code to detect insecure coding patterns.
A Go tool that transforms ASCII/UTF-8 characters to accented variants for password permutation and hashcat workflows.
Automated system tests for the HomeMatic (O)CCU ReGaHss logic layer engine using a Node.js testing framework.
Integrates Bright's DAST security scan engine directly into .NET unit tests to find vulnerabilities early.
A probing tool that generates controlled network traffic to verify if security sensors are receiving all relevant traffic in corporate networks.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.