Showing 36 of 955 projects
A security tool that visualizes and analyzes Windows Active Directory event logs to investigate malicious logon activity.
Cryptographically sign and verify data to safely pass it between trusted and untrusted environments.
A simple wrapper for Apple's Keychain APIs on iOS, watchOS, tvOS, and macOS, making secure storage as easy as NSUserDefaults.
A Windows security tool that reduces the attack surface by disabling risky features in Windows, Office, Adobe Reader, and LibreOffice.
Static code analysis tool for Kubernetes YAML and Helm charts that provides recommendations to improve reliability and security.
A microservices API gateway built on Node.js and Express.js for securing and exposing services in cloud-native architectures.
Securely share passwords, text, files, and URLs via self-destructing links with full audit logs.
A crowdsourced collection of websites with frustrating and counterproductive password requirements.
A Swift library providing simple helper functions for securely storing text and data in the iOS/macOS Keychain.
A non-Turing complete expression language for fast, safe, and portable evaluation with C-like syntax.
Open source Runtime Application Self-Protection (RASP) solution that integrates security directly into application servers via instrumentation.
A modern, open-source password manager for individuals and teams with end-to-end encryption and self-hosting capabilities.
A protocol-oriented Swift library for interacting with the iOS/macOS keychain with type-safe results.
A Composer package that blocks installation of PHP dependencies with known security vulnerabilities.
A lightweight, portable TLS/SSL library written in ANSI C for embedded systems, RTOS, and cloud applications.
A comprehensive list of all known public suffixes (like .com, .co.uk) under which internet users can directly register domain names.
A curated list of SSH applications, libraries, and resources for developers and system administrators.
A framework that generates randomly vulnerable virtual machines for security education, labs, and CTF events.
An SSH Certificate Authority that runs as an AWS Lambda function for ephemeral, IAM-controlled SSH access.
A security audit tool for Ruby projects that checks Gemfile.lock for vulnerable gem versions and insecure sources.
A Go library that creates a secure software enclave to protect sensitive data in memory from exposure and attacks.
Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.
A static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.
An open-source password manager built with Flutter, compatible with KeePass 2.x (KDBX 3 and KDBX 4) across all major platforms.
KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.
An automated security testing framework for REST APIs that detects vulnerabilities like SQL injection, XSS, and CSRF.
An ultra-high performance, stateless, declarative API Gateway written in Go for microservices and secure communications.
An Angular HTTP interceptor library for automatically attaching JSON Web Tokens (JWTs) to HttpClient requests.
A public repository for developing, testing, and maintaining detection rules for Elastic Security's SIEM, with tools for Detections as Code.
A CLI tool for managing secrets using AWS SSM Parameter Store and Secrets Manager as backends.
A Laravel service provider for generating and validating CAPTCHA images, including math-based challenges.
A retired iOS action extension that enabled 1Password to fill credentials and other data into third-party apps.
A phishing campaign toolkit for simulating real-world attacks to test and promote user security awareness.
A Python tool to dump a git repository from a website, even when directory listing is disabled.
A comprehensive security framework for Java applications, supporting authentication, authorization, and integration with multiple protocols and frameworks.
A Windows security tool for real-time adversary tradecraft detection, memory scanning, and forensics via behavior-driven rules.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.