Security

安全工具与实践

lwthiker/curl-impersonate

curl-impersonate: A special build of curl that can impersonate Chrome & Firefox

Python 7.0k 576 MIT
curl https security ssl +1

bleachbit/bleachbit

BleachBit system cleaner for Windows and Linux

Python 6.9k 455 GPL-3.0
antiforensics bleachbit ccleaner-alternative cleaner +16

microsoft/Security-101

8 Lessons, Kick-start Your Cybersecurity Learning.

HTML 6.9k 932 CC0-1.0
appsec cia-triad data-protection data-security +7

daffainfo/AllAboutBugBounty

All about bug bounty (bypasses, payloads, and etc)

6.9k 1.3k
bug bugbounty bugbountytips bypass +9

sottlmarek/DevSecOps

Ultimate DevSecOps library

6.9k 1.2k MIT
automation awesome awesome-list aws +15

fleetdm/fleet

Open device management

Go 6.9k 1.0k NOASSERTION
binary-authorization configuration-management device-management gitops +14

urbanadventurer/WhatWeb

Next generation web scanner

Ruby 6.8k 1.0k GPL-2.0
application-security appsec hacking hacking-tools +16

CTFd/CTFd

CTFs as you need them

Python 6.8k 2.8k Apache-2.0
ctf ctfd education flask +1

chaifeng/ufw-docker

To fix the Docker and UFW security flaw without disabling iptables

Shell 6.8k 498 GPL-3.0
debian docker docker-swarm firewall +4

AFLplusplus/AFLplusplus

The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!

C 6.8k 1.3k AGPL-3.0
afl afl-compiler afl-fuzz afl-fuzzer +11

superagent-ai/superagent

Superagent protects your AI applications against prompt injections, data leaks, and harmful outputs. Embed safety directly into your app and prove compliance to your customers.

TypeScript 6.7k 963 MIT
ai anthropic guardrails llm +3

infobyte/faraday

Open Source Vulnerability Management Platform

Python 6.7k 1.1k GPL-3.0
appsec burpsuite collaboration continuous-scanning +16

S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

6.7k 1.3k MIT
active-directory active-directory-cheatsheet active-directory-exploitation activedirectory +16

fulldecent/system-bus-radio

Transmits AM radio on computers without radio transmitting hardware.

C 6.7k 404 MIT
airgap communication communication-protocol electrical-engineering +11

OISF/suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.

C 6.6k 1.8k GPL-2.0
cybersecurity ids intrusion-detection-system intrusion-prevention-system +7

xairy/linux-kernel-exploitation

A collection of links related to Linux kernel security and exploitation

6.6k 1.1k CC-BY-4.0
exploit kernel-exploitation linux-kernel privilege-escalation +1

j3ssie/osmedeus

A Modern Orchestration Engine for Security

Go 6.6k 1.0k MIT
agentic-ai attack-surface-management bugbounty go +11

EdOverflow/bugbounty-cheatsheet

A list of interesting payloads, tips and tricks for bug bounty hunters.

6.6k 1.6k CC-BY-SA-4.0
bugbounty infosec payloads security

decalage2/awesome-security-hardening

A collection of awesome security hardening guides, tools and other resources

6.6k 685
awesome-list best-practices blue-team blueteam +10

reddelexc/hackerone-reports

Top disclosed reports from HackerOne

Python 6.5k 1.1k
bugbounty csrf hackerone idor +8

MISP/MISP

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

PHP 6.5k 1.6k AGPL-3.0
cti cybersecurity fraud-detection fraud-management +16

cowrie/cowrie

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Python 6.5k 1.1k NOASSERTION
attacker cowrie cowrie-ssh deception +12

zizmorcore/zizmor

Static analysis for GitHub Actions

Rust 6.5k 252 MIT
github-actions security security-tools static-analysis

lldap/lldap

Light LDAP implementation

Rust 6.5k 354 GPL-3.0
authentication ldap opaque rust +3

yeahhub/Hacking-Security-Ebooks

Top 100 Hacking & Security E-Books (Free Download)

6.5k 1.2k
books ebooks hacking hacking-security-ebooks +3

cleverhans-lab/cleverhans

An adversarial example library for constructing attacks, building defenses, and benchmarking both

Jupyter Notebook 6.5k 1.4k MIT
benchmarking machine-learning security

Tencent/AI-Infra-Guard

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

Python 6.4k 591 Apache-2.0
agent agent-security agentic-ai ai-infra +16

ikarus23/MifareClassicTool

An Android NFC app for reading, writing, analyzing, etc. MIFARE Classic RFID tags.

Java 6.4k 1.0k GPL-3.0
android android-nfc mifare mifare-classic +4

datreeio/datree

Prevent Kubernetes misconfigurations from reaching production (again 😤 )! From code to cloud, Datree provides an E2E policy enforcement solution to run automatic checks for rule violations. See our docs: https://hub.datree.io

Go 6.3k 356 Apache-2.0
admission-webhook best-practices cli datree +7

google/syzkaller

syzkaller is an unsupervised coverage-guided kernel fuzzer

Go 6.3k 1.4k Apache-2.0
fuzz-testing fuzzer fuzzing kernel +5