Security
安全工具与实践
YauhenKavalchuk/interview-questions
Популярные HTML / CSS / JavaScript / ECMAScript / TypeScript / React / Vue / Angular / Node вопросы на интервью и ответы на них (https://tinyurl.com/wxysrpsy)
dmno-dev/varlock
AI-safe .env files: Schemas for agents, Secrets for humans.
projectdiscovery/interactsh
An OOB interaction gathering server and client library
sensepost/gowitness
🔍 gowitness - a golang, web screenshot utility using Chrome Headless
google/santa
A binary authorization and monitoring system for macOS
firmianay/CTF-All-In-One
CTF竞赛权威指南
zer0yu/Awesome-CobaltStrike
List of Awesome CobaltStrike Resources
intuitem/ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 200+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
skerkour/black-hat-rust
Applied offensive security with Rust - https://kerkour.com/black-hat-rust
buttercup/buttercup-desktop
:key: Cross-Platform Passwords & Secrets Vault
Netflix/security_monkey
Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.
coreb1t/awesome-pentest-cheat-sheets
Collection of the cheat sheets useful for pentesting
smallstep/cli
🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc.
cilium/hubble
Hubble - Network, Service & Security Observability for Kubernetes using eBPF
CHYbeta/Web-Security-Learning
Web-Security-Learning
jtesta/ssh-audit
SSH server & client security auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)
lcvvvv/kscan
Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。
open-policy-agent/gatekeeper
🐊 Policy Controller for Kubernetes
ConsenSysDiligence/mythril
Mythril is a symbolic-execution-based securty analysis tool for EVM bytecode. It detects security vulnerabilities in smart contracts built for Ethereum and other EVM-compatible blockchains.
PaulSec/awesome-sec-talks
A collected list of awesome security talks
google/tamperchrome
Tamper Dev is an extension that allows you to intercept and edit HTTP/HTTPS requests and responses as they happen without the need of a proxy. Works across all operating systems (including Chrome OS).
DependencyTrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
PurpleI2P/i2pd
🛡 I2P: End-to-End encrypted and anonymous Internet
guelfoweb/knockpy
Knock Subdomain Scan
RetireJS/retire.js
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
square/Valet
Valet lets you securely store data in the iOS, tvOS, watchOS, or macOS Keychain without knowing a thing about how the Keychain works. It’s easy. We promise.
ivre/ivre
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.
nolabs-ai/nono
secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.
google/nsjail
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
briansmith/ring
An experiment.