Showing 36 of 1288 projects
A simple yet powerful ACMEv2 client for Windows to automate SSL/TLS certificate creation, installation, and renewal.
Rack middleware for blocking and throttling abusive requests in Ruby web applications.
An intentionally vulnerable Kubernetes cluster environment for hands-on security training and practice.
A curated list of awesome information security courses, training resources, and hands-on labs for cybersecurity professionals and students.
An authorization library for Ruby and Ruby on Rails that centralizes permission logic and restricts resource access.
An authorization library for Ruby and Ruby on Rails that centralizes permission logic and restricts resource access.
A high-performance, flexible authorization/permission engine inspired by Google Zanzibar for fine-grained access control.
Automatic TLS certificate issuance and renewal for Go programs, enabling fully-managed HTTPS with a single line of code.
A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
A comprehensive Python library for building OAuth and OpenID Connect clients and servers, with built-in JOSE support.
An open-source implementation of Google's Zanzibar authorization system, providing a scalable and customizable permission server.
Reference C implementation of Argon2, the memory-hard password hashing function that won the Password Hashing Competition.
A simple, secure, and fast identity management platform for self-hosted authentication, supporting OAuth2, LDAP, RADIUS, and Unix integration.
A mature low-level Linux container runtime focused on system containers with strong security features and kernel integration.
A flexible and versatile OAuth 2.0/OpenID Connect stack for implementing client, server, and token validation in .NET applications.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
A command-line tool for obfuscating Python scripts, binding them to specific machines, and setting expiration dates.
A penetration testing tool that discovers and accesses RTSP video surveillance cameras through network scanning and dictionary attacks.
A curated list of awesome projects, tutorials, and resources related to eBPF (extended Berkeley Packet Filter).
Open Source Host-based Intrusion Detection System performing log analysis, file integrity checking, rootkit detection, and active response.
A zero-trust identity and context-aware reverse proxy for secure, clientless access to internal web apps without a VPN.
eBPF-based real-time security observability and runtime enforcement for Kubernetes and Linux systems.
An open-source web application security scanner that identifies and exploits 200+ vulnerabilities for developers and penetration testers.
An open-source, high-performance Web Application Firewall (WAF) module for NGINX that blocks malicious web traffic by default.
A syntax highlighter and tool to semi-automatically rewrite shell scripts for ShellCheck conformance, focusing on proper quoting.
A collaborative collection of data and code quirks to improve password manager compatibility with websites.
A pure-Rust eBPF library focused on developer experience, operability, and compile-once-run-everywhere capabilities.
A curated list of awesome open-source tools, detection rules, datasets, and resources for threat detection and hunting.
A JavaScript interpreter for .NET that runs on any modern .NET platform, enabling JavaScript execution within .NET applications.
Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications at scale.
Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications at scale.
A security testing framework for Android that identifies vulnerabilities by interacting with apps, IPC endpoints, and the OS.
An open-core, language-agnostic authorization solution for implementing and managing context-aware access control policies.
A curated list of resources for learning about vehicle security, car hacking, and automotive tinkering.
A binary and file access authorization system for macOS that monitors and controls application execution.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.