Showing 36 of 119 projects
GEF is a modern GDB enhancement providing advanced debugging features for exploit developers and reverse engineers on Linux.
An open-source, large-scale network packet capture, indexing, and analysis system with a web interface.
A static analysis security vulnerability scanner for Ruby on Rails applications.
An open-source adversary emulation platform that simulates malware attacks to test and improve network security defenses.
A curated list of books, articles, websites, and tools for learning application security across multiple programming languages.
A curated list of books, articles, websites, and tools for learning application security across multiple programming languages.
A curated list of resources for learning and practicing web application security, including tools, books, courses, and vulnerable labs.
A simple wrapper for GPG to encrypt secrets in version control systems like Git, Mercurial, and Subversion.
An open-source, Google Zanzibar-inspired database for storing and querying fine-grained authorization data at scale.
A curated collection of security hardening guides, best practices, checklists, benchmarks, and tools for various systems and services.
An unsupervised coverage-guided kernel fuzzer for finding bugs in operating system kernels like Linux, Windows, and BSD variants.
A Python extension for GDB that enhances exploit development with colorized displays, security checks, and specialized commands.
A comprehensive, free information security reference covering techniques, tools, tactics, and resources for learning and professional development.
A curated list of bug bounty programs, write-ups, and resources for security researchers and ethical hackers.
A modular reconnaissance framework for conducting open source intelligence (OSINT) gathering from web-based sources.
A Python framework to automate the installation and updating of penetration testing tools on Debian/Ubuntu/ArchLinux systems.
An extensible Python framework for network forensic analysis through plugin-based dissection of packet captures.
A high-performance multiple regex matching library using hybrid automata for simultaneous pattern matching across data streams.
Open source CNAPP that hunts for threats in cloud native platforms, ranks them by risk, and visualizes attack paths.
A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
A comprehensive cheat sheet and tool collection for mobile application penetration testing, mapped to OWASP Mobile Top 10 risks.
An incident response framework for remote live forensics with Python client-server architecture.
A curated list of awesome free forensic analysis tools, resources, and learning materials for digital investigators.
A curated list of awesome free (mostly open source) forensic analysis tools and resources for digital investigations.
A penetration testing tool that discovers and accesses RTSP video surveillance cameras through network scanning and dictionary attacks.
A curated list of awesome open-source tools, detection rules, datasets, and resources for threat detection and hunting.
A tool to search for ROP gadgets in binary files to facilitate Return-Oriented Programming exploitation.
A source code analyzer that identifies features and characteristics in software components using static analysis and a JSON rules engine.
A Python script that discovers endpoints and their parameters in JavaScript files for penetration testing and bug hunting.
A curated collection of cheat sheets and resources for penetration testing and security assessments.
A static analysis tool that finds security vulnerabilities and misconfigurations in GitHub Actions workflows.
A curated list of awesome YARA rules, tools, and resources for malware researchers and security professionals.
A categorized collection of bug bounty write-ups organized by vulnerability type for security researchers.
A penetration testing tool that detects and exploits Server-Side Template Injection (SSTI) and code injection vulnerabilities.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.