Showing 18 of 18 projects
A fast, customizable vulnerability scanner with a YAML-based DSL, powered by a global security community.
An enterprise-friendly Python tool for detecting and preventing secrets from entering codebases with a baseline approach.
A Windows security tool for real-time adversary tradecraft detection, memory scanning, and forensics via behavior-driven rules.
A grep-based source code auditing tool that finds potential security flaws using signature databases for multiple programming languages.
Open-source supply chain security scanner that automatically detects vulnerabilities like Log4Shell in dependencies and notifies via GitHub pull requests.
A curated collection of offensive security research, techniques, and tools for attacking CI/CD pipelines and software supply chains.
A system-focused web application for tracking systems, tasks, and artifacts during major digital forensics and incident response (DFIR) investigations.
A DevOps-first CLI tool for documenting threat models using HashiCorp Configuration Language (HCL).
A low-level mutator for Windows PE files that obfuscates headers and metadata to break static analysis signatures without breaking execution.
A Django web application for static security analysis (SAST) and malware detection in Android APKs.
An automated multi-cloud deployment tool for red team infrastructure, built on Terraform with AI-powered orchestration.
A research project inventorying RCE-by-design features and code execution risks in CI/CD pipeline tools.
A fast IDA Pro headless plugin that extracts decompiled pseudocode for vulnerability research and static analysis.
Fast, parallel, cross-variant ROP/JOP gadget search tool for x86/x64 binaries, supporting exploit development.
A Python tool that automates the provisioning of AWS p3 GPU instances via Terraform for high-speed password cracking with Hashcat.
OWASP's software composition analysis tool that identifies project dependencies and checks for known vulnerabilities.
An intentionally vulnerable web application for measuring and improving XSS detection in security testing tools.
A Suricata syntax highlighter with experimental warning/error detection for Sublime Text.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.