Showing 36 of 955 projects
Adds per-object permissions to Django's authorization system, enabling fine-grained access control.
A secure and easy-to-use PHP library for encrypting data with keys or passwords.
A pure JavaScript steganography module that hides secrets inside text using invisible unicode characters, secured with passwords and encryption.
An Nmap NSE script that transforms nmap into a vulnerability scanner using offline vulnerability databases.
Simple, Heroku-friendly Rails app configuration using ENV and a single YAML file.
An open-source Cloud Security Posture Management (CSPM) tool that scans AWS, Azure, GCP, Oracle, and GitHub for security misconfigurations.
OpenID Certified OAuth 2.0 Authorization Server implementation for Node.js with extensive spec support.
A fast, configurable HTML sanitizer for Go that scrubs user-generated content of XSS attacks using an allowlist policy.
A Ruby implementation of the RFC 7519 OAuth JSON Web Token (JWT) standard for secure token encoding and decoding.
A lightweight, fast, always-up HTTP reverse proxy built in Rust, configurable at runtime without reloading.
A Docker container providing a secure Nginx web server and reverse proxy with automated SSL certificates and fail2ban protection.
A reverse engineering framework and command-line toolset for binary analysis, disassembly, debugging, and forensic tasks.
An elegant, framework-agnostic package for managing roles and abilities in Laravel using Eloquent models.
A cloud native Identity & Access Proxy (IAP) and Access Control Decision API that authenticates, authorizes, and mutates HTTP requests.
A PHP client library for Google's reCAPTCHA service to verify user responses and protect websites from spam.
A fast, standalone tool for rapid threat hunting and forensic analysis of Windows event logs and other forensic artefacts.
Atomic and non-atomic counters and rate limiting tools for Node.js, Deno, and browsers to protect from DoS and brute force attacks.
A cross-platform desktop application for managing passwords and sensitive data, built with Electron and Angular.
An open-source, enterprise-grade Web Application Firewall library written in Go, compatible with ModSecurity SecLang rulesets.
A Rust implementation of the age file encryption tool, offering simple, secure encryption with small explicit keys and UNIX-style composability.
A curated collection of proof-of-concept exploits for Common Vulnerabilities and Exposures (CVEs).
A batteries-included framework for building authorization in your application with a declarative policy language.
An open-source firmware security analyzer for embedded Linux devices, performing extraction, static/dynamic analysis, SBOM generation, and vulnerability reporting.
A modern, web-based SSH console and key management tool that functions as a secure bastion host.
A collection of reusable, vendor-neutral, and industry-specific solution architecture patterns for building enterprise software systems.
A collection of reusable, vendor-neutral, industry-specific, and vendor-specific solution architecture patterns for building enterprise software systems.
An open-source Ethereum consensus client written in Rust, designed for security and performance on the Ethereum proof-of-stake network.
A fully managed, high-performance FTP and FTPS client library for .NET and .NET Standard, optimized for speed.
A standalone tool that finds unprotected secrets like passwords and API keys in container images and file systems.
An open-source implementation of FIDO2 and U2F security keys written in Rust, enabling custom hardware authentication devices.
A security-oriented, feedback-driven, evolutionary software fuzzer that uses hardware and software code coverage to find bugs.
An open-source tool for collaborative forensic timeline analysis, enabling teams to organize, annotate, and investigate timelines together.
A standards-compliant HTML filtering library for PHP that removes malicious code while preserving safe markup.
A client and server implementation of The Update Framework (TUF) for securing software distribution and updates.
Chrome extension and Express server demonstrating a CSS-based keylogging attack on password inputs.
An open-source webhooks service that handles deliverability, retries, and security with a single API call.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.