security-tools
Tracked open-source repos tagged security-tools, sorted by stars.
- #181
Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.
★ 1,236+0Star change over the last 7 days - #182★ 1,217+0Star change over the last 7 days
- #183★ 1,203+0Star change over the last 7 days
- #184
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
★ 1,202+0Star change over the last 7 days - #185
Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.
★ 1,200+0Star change over the last 7 days - #186
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
★ 1,193+0Star change over the last 7 days - #187★ 1,191+0Star change over the last 7 days
- #188
Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess
★ 1,182+0Star change over the last 7 days - #189
Reversense (Dexcalibur2) is a fully rewriting and rethinking of Dexcalibur. Reversense is a binary intelligence platform that automates the reverse engineering of mobile and embedded applications.
★ 1,168+0Star change over the last 7 days - #190★ 1,160+0Star change over the last 7 days
- #191
Verify apps easily.
★ 1,153+0Star change over the last 7 days - #192★ 1,124+6Star change over the last 7 days
- #193
An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE methodology.
★ 1,116+4Star change over the last 7 days - #194
SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks against PBX systems especially through identification, scanning, extension enumeration and password cracking.
★ 1,101+2Star change over the last 7 days - #195
AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.
★ 1,095+0Star change over the last 7 days - #196★ 1,089+1Star change over the last 7 days
- #197
Stop your AI from making things up — it proposes, deterministic tools decide, every claim checked against ground truth with evidence. Grounded facts and context survive resets. Reverse engineering is the proving ground. MCP server + CLI.
★ 1,089+475Star change over the last 7 days - #198
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
★ 1,077+0Star change over the last 7 days - #199★ 1,077+0Star change over the last 7 days
- #200
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
★ 1,075+23Star change over the last 7 days - #201★ 1,072+0Star change over the last 7 days
- #202
最好用最智能最可控的目录Fuzz工具 | The most powerful, user-friendly, intelligent, and precise HTTP Fuzzer.
★ 1,059+2Star change over the last 7 days - #203
Statically-linked ssh server with reverse shell functionality for CTFs and such
★ 1,056+0Star change over the last 7 days - #204★ 1,053+1Star change over the last 7 days
- #205
A security scanner for your LLM agentic workflows
★ 1,048+3Star change over the last 7 days - #206
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks
★ 1,045+0Star change over the last 7 days - #207★ 1,043+2Star change over the last 7 days
- #208
Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.
★ 1,038+0Star change over the last 7 days - #209★ 1,011+5Star change over the last 7 days
- #210
基于ARL-V2.6.2修改后的版本
★ 1,005+0Star change over the last 7 days