Showing 36 of 928 projects
A multi-language, cross-platform cryptographic library designed to be secure, easy to use correctly, and hard to misuse.
A curated collection of web security resources, tools, and research materials for learning penetration techniques.
An open-source exploitation framework dedicated to embedded devices for penetration testing and vulnerability assessment.
A free and open-source network discovery and security auditing tool for mapping networks and identifying services.
A free, cross-platform password manager compatible with KeePass databases, available as a web app and desktop application.
A forensic toolkit for gathering and analyzing traces on Android and iOS devices to identify potential spyware compromise.
A community guide to using YubiKey as a smart card for GnuPG and SSH with hardware-secured cryptographic keys.
A vulnerability scanner for container images, filesystems, and SBOMs to detect known security issues.
A vulnerability scanner for container images, filesystems, and SBOMs to detect known security issues.
An open-source, general-purpose policy engine for unified, context-aware policy enforcement across the stack.
A curated list of Capture The Flag (CTF) frameworks, libraries, resources, software, and tutorials for security enthusiasts.
A curated list of Capture The Flag (CTF) frameworks, libraries, resources, software, and tutorials for security enthusiasts.
A Laravel and Lumen package for JSON Web Token authentication, providing stateless API authentication.
A private messaging platform with no user identifiers, using disposable relay nodes for metadata protection.
A comprehensive collection of iOS development best practices, covering architecture, tools, security, and deployment.
An open-source, next-generation Web Application Firewall (WAF) that integrates as a reverse proxy to make web services secure by default.
An open-source, next-generation Web Application Firewall (WAF) based on NGINX that makes web services secure by default.
A comprehensive collection of cryptographic algorithms implemented in pure Swift for Apple platforms and Linux.
A generic and open signature format for describing log event detections, shareable across SIEM systems.
A generic and open signature format for describing log event detections, shareable across SIEM systems.
A curated list of awesome open-source threat intelligence resources, including feeds, tools, platforms, and standards.
A PowerShell framework for offensive security, penetration testing, and red teaming with scripts for all phases.
Open-source disk encryption software with enhanced security features, based on TrueCrypt.
Transparently encrypts specific files in git repositories, allowing secure storage of secrets alongside public code.
Standard libraries and queries for CodeQL, powering GitHub Advanced Security and static application security testing.
A Let's Encrypt/ACME client and library written in Go for automatic certificate management.
A script that checks for dozens of common best-practices around deploying Docker containers in production.
A free, open-source WordPress security scanner for professionals and site maintainers to test website vulnerabilities.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and reverse engineering.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and penetration testing.
A PKI/TLS toolkit for signing, verifying, and bundling TLS certificates, available as a CLI tool and HTTP API server.
An all-in-one, optionally distributed, multi-architecture honeypot platform with 20+ honeypots, visualization via Elastic Stack, and live attack maps.
A runtime mobile exploration toolkit powered by Frida for security assessment of iOS and Android apps without jailbreak.
A Kubernetes controller and tool for encrypting Secrets into SealedSecrets that can be safely stored in Git.
A Go implementation of JSON Web Tokens (JWT) for signing, verifying, parsing, and generating tokens.
A curated list of tools and resources for digital forensics and incident response (DFIR) teams.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.