Showing 36 of 1287 projects
A framework that generates randomly vulnerable virtual machines for security education, labs, and CTF events.
An SSH Certificate Authority that runs as an AWS Lambda function for ephemeral, IAM-controlled SSH access.
A security audit tool for Ruby projects that checks Gemfile.lock for vulnerable gem versions and insecure sources.
A Go library that creates a secure software enclave to protect sensitive data in memory from exposure and attacks.
Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.
A static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.
An open-source password manager built with Flutter, compatible with KeePass 2.x (KDBX 3 and KDBX 4) across all major platforms.
KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.
The future of online communications.
A public repository for developing, testing, and maintaining detection rules for Elastic Security's SIEM, with tools for Detections as Code.
An ultra-high performance, stateless, declarative API Gateway written in Go for microservices and secure communications.
An automated security testing framework for REST APIs that detects vulnerabilities like SQL injection, XSS, and CSRF.
An Angular HTTP interceptor library for automatically attaching JSON Web Tokens (JWTs) to HttpClient requests.
A CLI tool for managing secrets using AWS SSM Parameter Store and Secrets Manager as backends.
A Python tool to dump a git repository from a website, even when directory listing is disabled.
A Laravel service provider for generating and validating CAPTCHA images, including math-based challenges.
A retired iOS action extension that enabled 1Password to fill credentials and other data into third-party apps.
A phishing campaign toolkit for simulating real-world attacks to test and promote user security awareness.
A comprehensive security framework for Java applications, supporting authentication, authorization, and integration with multiple protocols and frameworks.
A Windows security tool for real-time adversary tradecraft detection, memory scanning, and forensics via behavior-driven rules.
A semi-automatic OSINT framework and package manager for gathering intelligence and enumerating attack surfaces.
A modern PHP compiler and runtime for .NET/.NET Core, enabling PHP code to run within the .NET ecosystem.
A Go library for fine-grained, policy-based access control inspired by AWS IAM, designed for microservices and IoT.
A powerful, easily deployable network traffic analysis tool suite for PCAP files, Zeek logs, and Suricata alerts.
A Go package that adds OpenID Connect client support to the standard OAuth2 library.
A comprehensive Nginx configuration template with optimized defaults, SSL setup, and Docker integration.
A peer-to-peer encrypted global filesystem and private web platform with secure file storage, social networking, and application hosting.
A SpotBugs plugin for detecting security vulnerabilities in Java web and Android applications.
The OWASP Mobile Application Security Verification Standard (MASVS) is the industry standard for mobile app security.
A complete Go implementation of JOSE (JWA/JWE/JWK/JWS/JWT) for signing, encryption, and key management.
Adds OAuth1.0a and OAuth2 authentication support to Symfony applications with 58+ provider integrations.
A PHP class for detecting bots, crawlers, and spiders via user agent and HTTP headers.
A universal JavaScript library for implementing OAuth 2.0 and OpenID Connect client flows across Node.js, browsers, Deno, and other runtimes.
A flexible Go package for generating and verifying captchas as base64-encoded image or audio strings.
A Perl engine that routes all your internet traffic through the Tor network for enhanced privacy and anonymity.
A curated list of software, hardware, books, and research for embedded and IoT security analysis.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.