Showing 36 of 1287 projects
Rack middleware for blocking and throttling abusive requests in Ruby web applications.
A simple yet powerful ACMEv2 client for Windows to automate SSL/TLS certificate creation, installation, and renewal.
An intentionally vulnerable Kubernetes cluster environment for hands-on security training and practice.
A curated list of awesome information security courses, training resources, and hands-on labs for cybersecurity professionals and students.
An authorization library for Ruby and Ruby on Rails that centralizes permission logic and restricts resource access.
An authorization library for Ruby and Ruby on Rails that centralizes permission logic and restricts resource access.
Automatic TLS certificate issuance and renewal for Go programs, enabling fully-managed HTTPS with a single line of code.
A high-performance, flexible authorization/permission engine inspired by Google Zanzibar for fine-grained access control.
A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
An open-source implementation of Google's Zanzibar authorization system, providing a scalable and customizable permission server.
A comprehensive Python library for building OAuth and OpenID Connect clients and servers, with built-in JOSE support.
Reference C implementation of Argon2, the memory-hard password hashing function that won the Password Hashing Competition.
A mature low-level Linux container runtime focused on system containers with strong security features and kernel integration.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
A flexible and versatile OAuth 2.0/OpenID Connect stack for implementing client, server, and token validation in .NET applications.
A simple, secure, and fast identity management platform for self-hosted authentication, supporting OAuth2, LDAP, RADIUS, and Unix integration.
A command-line tool for obfuscating Python scripts, binding them to specific machines, and setting expiration dates.
A penetration testing tool that discovers and accesses RTSP video surveillance cameras through network scanning and dictionary attacks.
A curated list of awesome projects, tutorials, and resources related to eBPF (extended Berkeley Packet Filter).
Open Source Host-based Intrusion Detection System performing log analysis, file integrity checking, rootkit detection, and active response.
A zero-trust identity and context-aware reverse proxy for secure, clientless access to internal web apps without a VPN.
An open-source web application security scanner that identifies and exploits 200+ vulnerabilities for developers and penetration testers.
eBPF-based real-time security observability and runtime enforcement for Kubernetes and Linux systems.
An open-source, high-performance Web Application Firewall (WAF) module for NGINX that blocks malicious web traffic by default.
A syntax highlighter and tool to semi-automatically rewrite shell scripts for ShellCheck conformance, focusing on proper quoting.
A collaborative collection of data and code quirks to improve password manager compatibility with websites.
A pure-Rust eBPF library focused on developer experience, operability, and compile-once-run-everywhere capabilities.
A curated list of awesome open-source tools, detection rules, datasets, and resources for threat detection and hunting.
A JavaScript interpreter for .NET that runs on any modern .NET platform, enabling JavaScript execution within .NET applications.
Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications at scale.
Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications at scale.
A security testing framework for Android that identifies vulnerabilities by interacting with apps, IPC endpoints, and the OS.
A binary and file access authorization system for macOS that monitors and controls application execution.
An open-core, language-agnostic authorization solution for implementing and managing context-aware access control policies.
A Golang command-line utility that uses Chrome Headless to capture website screenshots and gather web data.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.