Pentest, defense, crypto
100 repositories
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
pure-python ECDSA signature/verification and ECDH key agreement
🔐 oauth2 - A Ruby wrapper for the OAuth 2.0, & 2.1 Authorization Frameworks, including OpenID Connect (OIDC)
Free and open log management
A static analysis security vulnerability scanner for Ruby on Rails applications
Tenzir is the data pipeline engine for security teams.
Bitcoin Core integration/staging tree
Low code web framework for real world applications, in Python and Javascript
Daemon to ban hosts that cause multiple authentication errors
Decentralized cryptocurrency blockchain daemon implementing the XRP Ledger protocol in C++
GNU Radio – the Free and Open Software Radio Ecosystem
🔐 Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.
Spring Security
Security engine for Java (authentication, authorization, multi frameworks): OpenID Connect, SAML2, CAS, OAuth, LDAP, JWT...
Help secure Express apps with various HTTP headers
An open-source, privacy-enhancing web browser for iOS, utilizing the Tor anonymity network
Nmap - the Network Mapper. Github mirror of official SVN repository.
An advanced SAT solver
🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.
OpenVPN is an open source VPN daemon
Automatic SQL injection and database takeover tool
Arkime is an open source, large scale, full packet capturing, indexing, and database system.
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com
Bridge from the pac4j security library to Shiro
An ArchLinux based distribution for penetration testers and security researchers.
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
Security library for Play framework 2/3 in Java and Scala: OpenID Connect, SAML2, CAS, OAuth, LDAP, JWT...
General purpose TLS and crypto library
A modern, portable, easy to use crypto library.
Bastillion gives you a clean, browser-based way to manage SSH access across all your systems—like a bastion host with a friendly dashboard.
Patch-level verification for Bundler
An Android NFC app for reading, writing, analyzing, etc. MIFARE Classic RFID tags.
Cryptography Toolkit
The best authentication plugin for the Bukkit/Spigot API!
Captcha for Laravel 5+
the TCPdump network dissector
Web path scanner
Damn Vulnerable Web Application (DVWA)
Sample application for Phalcon Framework (Acl, Auth, Security)
Instant switching between user accounts in WordPress and WooCommerce.
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
🛡 I2P: End-to-End encrypted and anonymous Internet
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux and Ubuntu.
Capstone disassembly/disassembler framework for ARM, ARM64 (ARMv8), Alpha, BPF, Ethereum VM, HPPA, LoongArch, M68K, M680X, Mips, MOS65XX, PPC, RISC-V(rv32G/rv64G), SH, Sparc, SystemZ, TMS320C64X, TriCore, Webassembly, XCore and X86.
Free Elasticsearch security plugin and Kibana security plugin: super-easy Kibana multi-tenancy, Encryption, Authentication, Authorization, Auditing
A Python wrapper around the OpenSSL library
Advanced vm/sandbox for Node.js
Portable OpenSSH
Cryptomator for Windows, macOS, and Linux: Secure client-side encryption for your cloud storage, ensuring privacy and control over your data.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
Platform Security Assessment Framework
BleachBit system cleaner for Windows and Linux
List of sites with two factor auth support which includes SMS, email, phone calls, hardware, and software.
This chef cookbook provides numerous security-related configurations, providing all-round base protection.
hydra
Security automation content in SCAP, Bash, Ansible, and other formats
Monero: the secure, private, untraceable cryptocurrency
The Github home of Orbot: Tor on Android (Also available on gitlab!)
Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search
Collaborative forensic timeline analysis
wolfSSH is a small, fast, portable SSH implementation, including support for SCP and SFTP.
An implementation of the TLS/SSL protocols
Gitbook documentation for libsodium
CryptoSwift is a growing collection of standard and secure cryptographic algorithms implemented in Swift
A collection of android security related resources
Libtpms-based TPM emulator with socket, character device, and Linux CUSE interface.
Bluetooth Low Energy (BLE) packet sniffer and transmitter for both standard and non standard (raw bit) based on Software Defined Radio (SDR).
SQL powered operating system instrumentation, monitoring, and analytics.
An open source cybersecurity protocol for syncing decentralized graph data.
A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the AI-driven world.
Golang (GO) implementation of Javascript Object Signing and Encryption specification
Web application acceleration, advanced DDoS protection and web security
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
The Rogue Access Point Framework
A Rust port of shadowsocks
:closed_lock_with_key: Security advisories as a simple composer exclusion list, updated daily
Directory/File, DNS and VHost busting tool written in Go
🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
Malicious traffic detection system
Basic rate-limiting middleware for the Express web server
The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS 1.3! Update to wolfSSL 5.9.1 for the latest CVE fixes.
Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
The easiest, and most secure way to access and protect all of your infrastructure.
🌏 A tiny 0-dependency thread-safe Java™ lib for setting/viewing dns programmatically without touching host file, make unit/integration testing portable; and a tiny tool for setting/viewing dns of running JVM process.
edb is a cross-platform AArch32/x86/x86-64 debugger.
MiniCPS: a framework for Cyber-Physical Systems real-time simulation, built on top of mininet
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
Open Source Deep Packet Inspection Software Toolkit
A list of web application security
Security library for Sparkjava: OpenID Connect, SAML2, CAS, OAuth, LDAP, JWT...
ZAP Add-ons
Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.