Security

安全工具与实践

YauhenKavalchuk/interview-questions

Популярные HTML / CSS / JavaScript / ECMAScript / TypeScript / React / Vue / Angular / Node вопросы на интервью и ответы на них (https://tinyurl.com/wxysrpsy)

4.5k 594
accessibility angular css ecmascript +12

dmno-dev/varlock

AI-safe .env files: Schemas for agents, Secrets for humans.

TypeScript 4.5k 121 MIT
configuration dotenv env env-vars +3

projectdiscovery/interactsh

An OOB interaction gathering server and client library

Go 4.5k 483 MIT
appsec bugbounty dns golang +7

sensepost/gowitness

🔍 gowitness - a golang, web screenshot utility using Chrome Headless

Go 4.5k 456 GPL-3.0
chrome chrome-headless fingerprint footprinting +7

google/santa

A binary authorization and monitoring system for macOS

Objective-C++ 4.5k 288 Apache-2.0
allowlist authorization blocklist endpoint-security +4

firmianay/CTF-All-In-One

CTF竞赛权威指南

C 4.5k 709 CC-BY-SA-4.0
book crypto ctf exploit +6

zer0yu/Awesome-CobaltStrike

List of Awesome CobaltStrike Resources

4.4k 759
cobalt-strike redteam security

intuitem/ciso-assistant-community

CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 200+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.

Python 4.4k 836 NOASSERTION
audit automation bsi cis +16

skerkour/black-hat-rust

Applied offensive security with Rust - https://kerkour.com/black-hat-rust

Rust 4.4k 440 MIT
audit beacon bug-bounty bug-hunting +16

buttercup/buttercup-desktop

:key: Cross-Platform Passwords & Secrets Vault

TypeScript 4.4k 340 GPL-3.0
buttercup electron encryption login +3

Netflix/security_monkey

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

Python 4.4k 778 Apache-2.0
aws aws-ec2 aws-iam aws-policy-tracking +9

coreb1t/awesome-pentest-cheat-sheets

Collection of the cheat sheets useful for pentesting

4.4k 792
awesome cheatsheet penetration-testing pentest +3

smallstep/cli

🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc.

Go 4.3k 319 Apache-2.0
certificate cryptography encryption jose +13

cilium/hubble

Hubble - Network, Service & Security Observability for Kubernetes using eBPF

Makefile 4.3k 300 Apache-2.0
cilium ebpf kubernetes metrics +4

CHYbeta/Web-Security-Learning

Web-Security-Learning

HTML 4.3k 1.0k
security sqlinjection xss

jtesta/ssh-audit

SSH server & client security auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)

Python 4.3k 227 MIT
auditing security ssh

lcvvvv/kscan

Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。

Go 4.3k 545 GPL-3.0
brute-force bruteforce exploit fingerprint +6

open-policy-agent/gatekeeper

🐊 Policy Controller for Kubernetes

Go 4.3k 882 Apache-2.0
admission cncf gatekeeper hacktoberfest +7

ConsenSysDiligence/mythril

Mythril is a symbolic-execution-based securty analysis tool for EVM bytecode. It detects security vulnerabilities in smart contracts built for Ethereum and other EVM-compatible blockchains.

Python 4.3k 819 MIT
blockchain ethereum program-analysis security +4

PaulSec/awesome-sec-talks

A collected list of awesome security talks

4.2k 490
conferences hacking infosec security

google/tamperchrome

Tamper Dev is an extension that allows you to intercept and edit HTTP/HTTPS requests and responses as they happen without the need of a proxy. Works across all operating systems (including Chrome OS).

TypeScript 4.2k 232 Apache-2.0
debugging extension security web

DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Java 4.2k 814 Apache-2.0
appsec bill-of-materials bom component-analysis +16

PurpleI2P/i2pd

🛡 I2P: End-to-End encrypted and anonymous Internet

C++ 4.2k 513 BSD-3-Clause
anonymity c-plus-plus communication cryptography +7

guelfoweb/knockpy

Knock Subdomain Scan

Python 4.2k 874 GPL-3.0
bugbounty knockpy penetration-testing security +3

RetireJS/retire.js

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

JavaScript 4.2k 440 Apache-2.0
build-tool chrome-extension firefox-extension grunt-plugins +10

square/Valet

Valet lets you securely store data in the iOS, tvOS, watchOS, or macOS Keychain without knowing a thing about how the Keychain works. It’s easy. We promise.

Swift 4.2k 227 Apache-2.0
crypto face-id ios keychain +5

ivre/ivre

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.

Python 4.1k 701 GPL-3.0
bro easm external-attack-surface-management hacktoberfest +16

nolabs-ai/nono

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

Rust 4.1k 271 Apache-2.0
agent-sandbox agent-security ai-agent-sandbox ai-agent-security +11

google/nsjail

A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.

C++ 4.1k 372 Apache-2.0
chroot linux linux-namespaces process-isolation +2

briansmith/ring

An experiment.

Assembly 4.1k 804 NOASSERTION
cryptography rust security