Showing 36 of 389 projects
A curated collection of web security resources, tools, and research materials for learning penetration techniques.
An open-source, participative security engine that detects and blocks malicious IPs using crowdsourced threat intelligence.
An open-source exploitation framework dedicated to embedded devices for penetration testing and vulnerability assessment.
A free, cross-platform password manager compatible with KeePass databases, available as a web app and desktop application.
A free and open-source network discovery and security auditing tool for mapping networks and identifying services.
A forensic toolkit for gathering and analyzing traces on Android and iOS devices to identify potential spyware compromise.
A community guide to using YubiKey as a smart card for GnuPG and SSH with hardware-secured cryptographic keys.
A vulnerability scanner for container images, filesystems, and SBOMs to detect known security issues.
A vulnerability scanner for container images, filesystems, and SBOMs to detect known security issues.
An open-source, general-purpose policy engine for unified, context-aware policy enforcement across the stack.
A Laravel and Lumen package for JSON Web Token authentication, providing stateless API authentication.
A curated list of Capture The Flag (CTF) frameworks, libraries, resources, software, and tutorials for security enthusiasts.
A curated list of Capture The Flag (CTF) frameworks, libraries, resources, software, and tutorials for security enthusiasts.
A comprehensive collection of iOS development best practices, covering architecture, tools, security, and deployment.
A private messaging platform with no user identifiers, using disposable relay nodes for metadata protection.
A comprehensive collection of cryptographic algorithms implemented in pure Swift for Apple platforms and Linux.
A generic and open signature format for describing log event detections, shareable across SIEM systems.
A generic and open signature format for describing log event detections, shareable across SIEM systems.
An open-source, next-generation Web Application Firewall (WAF) based on NGINX that makes web services secure by default.
An open-source, next-generation Web Application Firewall (WAF) that integrates as a reverse proxy to make web services secure by default.
A curated list of awesome open-source threat intelligence resources, including feeds, tools, platforms, and standards.
A PowerShell framework for offensive security, penetration testing, and red teaming with scripts for all phases.
Open-source disk encryption software with enhanced security features, based on TrueCrypt.
A script that checks for dozens of common best-practices around deploying Docker containers in production.
Transparently encrypts specific files in git repositories, allowing secure storage of secrets alongside public code.
A free, open-source WordPress security scanner for professionals and site maintainers to test website vulnerabilities.
Standard libraries and queries for CodeQL, powering GitHub Advanced Security and static application security testing.
A Let's Encrypt/ACME client and library written in Go for automatic certificate management.
A PKI/TLS toolkit for signing, verifying, and bundling TLS certificates, available as a CLI tool and HTTP API server.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and penetration testing.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and reverse engineering.
An all-in-one, optionally distributed, multi-architecture honeypot platform with 20+ honeypots, visualization via Elastic Stack, and live attack maps.
A Kubernetes controller and tool for encrypting Secrets into SealedSecrets that can be safely stored in Git.
A runtime mobile exploration toolkit powered by Frida for security assessment of iOS and Android apps without jailbreak.
A Go implementation of JSON Web Tokens (JWT) for signing, verifying, parsing, and generating tokens.
A curated list of tools and resources for digital forensics and incident response (DFIR) teams.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.