Showing 36 of 386 projects
A multi-platform client-server tool for distributing Hashcat password cracking tasks across multiple computers.
A curated list of threat modeling resources including books, courses, videos, tools, tutorials, and examples for learning and practicing threat modeling.
An open-source tool for PostgreSQL and MySQL database anonymization, synthetic data generation, and logical dumping.
A curated list of DevSecOps tools, resources, and training materials for integrating security into the development lifecycle.
A grep-based source code auditing tool that finds potential security flaws using signature databases for multiple programming languages.
A modern hash identification tool that names MD5, SHA256, and 300+ other hash types with popularity ratings and summaries.
A machine learning security engine that preemptively prevents web app and API threats using supervised and unsupervised models.
A Python tool for calculating RSA and RSA-CRT cryptographic parameters and generating OpenSSL-compatible keys.
An automated framework for monitoring and tampering with system API calls of native macOS, iOS, and Android apps using Frida.
Upstream repository for the Security Enhanced Linux (SELinux) userland libraries and tools, complementing the kernel's mandatory access control features.
A collection of small, chainable command-line utilities for advanced password cracking operations.
The largest open-source database of regex patterns for detecting secrets, API keys, passwords, and tokens in code.
A command-line tool that detects steganographically hidden data in PNG and BMP image files.
A curated list of awesome resources, tools, and literature on executable packing, unpacking, and detection for malware analysis and cybersecurity.
A web-based tool for deobfuscating and unpacking JavaScript code, supporting multiple obfuscation formats.
A curated list of open-source .NET deobfuscators and unpackers for reversing protected assemblies.
A Python tool for analyzing and breaking multi-byte XOR ciphers by guessing key length and content.
A fully managed, cross-platform .NET library for capturing network packets from live devices and files.
A Python tool for analyzing PDF files to detect malicious content and perform security research.
A Qt and C++ GUI for the radare2 reverse engineering framework, designed to make binary analysis accessible.
A multiplatform open-source framework for binary analysis and reverse engineering, supporting x86 and ARM architectures.
A portable, extensible incident response tool that automates forensic artifact collection across Unix-like systems.
A multithreaded PDF password cracking utility with structured search builders, checkpoint/resume, and optimized performance.
A portable Python script that automates malware analysis by collecting runtime indicators using Sysinternals Procmon.
Automated deployment of red team infrastructure using Docker with a web interface for managing offensive security tools.
A community-sourced, machine-readable knowledge base of digital forensic artifacts for use in forensic tools and investigations.
A curated collection of fascinating and bizarre Censys Search queries for discovering exposed devices and services.
A collection of practical security-focused guides and checklists for smart contract development.
A CLI tool that audits API specifications, validates OpenAPI compliance, and runs security tests to prevent undefined user behavior.
A Terraform module to configure AWS accounts with a secure baseline aligned to CIS AWS Foundations and AWS Foundational Security Best Practices.
A modular vulnerability scanner that checks website security and automatically generates easy-to-read reports for organizations.
A Go program that reverse engineers Docker images to reconstruct the original Dockerfile.
A tool to create multiple TOR instances with load-balancing for increased anonymity and distributed traffic.
A collection of tools and scripts for unpacking and analyzing protected Android applications, originally presented at Defcon 22.
A virtual machine for Android application security assessment, reverse engineering, and malware analysis.
A lightweight Certificate Transparency log monitor that alerts you when SSL/TLS certificates are issued for your domains.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.