security
Tracked open-source repos tagged security, sorted by stars.
- #631
Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more
★ 1,477+0Star change over the last 7 days - #632
Awesome Vulnerable Applications
★ 1,477+0Star change over the last 7 days - #633★ 1,473+0Star change over the last 7 days
- #634
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
★ 1,469+0Star change over the last 7 days - #635
Infra provides authentication and access management to servers and Kubernetes clusters.
★ 1,467+0Star change over the last 7 days - #636★ 1,464+0Star change over the last 7 days
- #637★ 1,463+0Star change over the last 7 days
- #638
Username tools for penetration testing
★ 1,462+0Star change over the last 7 days - #639
Vulnerable app with examples showing how to not use secrets
★ 1,459+0Star change over the last 7 days - #640
Community-driven baseline to accelerate Intune adoption and learning.
★ 1,457+0Star change over the last 7 days - #641
Qtap: An eBPF agent that captures pre-encrypted network traffic, providing rich context about egress connections and their originating processes.
★ 1,456+0Star change over the last 7 days - #642
Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.
★ 1,454+0Star change over the last 7 days - #643★ 1,454+0Star change over the last 7 days
- #644
🔐 Run frida-server on boot with Magisk, always up-to-date
★ 1,453+0Star change over the last 7 days - #645
Privacy-first PDF utility (Zero-Server Architecture). Merge, split, compress, and edit PDFs 100% locally on your device. No uploads, no servers, no tracking.
★ 1,444+0Star change over the last 7 days - #646
UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
★ 1,441+0Star change over the last 7 days - #647
FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.
★ 1,437+0Star change over the last 7 days - #648
LLM powered fuzzing via OSS-Fuzz.
★ 1,434+0Star change over the last 7 days - #649
🔐 Out of the box stateless openvpn-server docker image which starts in less than 2 seconds
★ 1,428+0Star change over the last 7 days - #650
保护你的浏览器指纹 | Protect Your Browser Fingerprints | Chrome, Edge, Firefox | 扩展 / Extension
★ 1,422+0Star change over the last 7 days - #651
📗 How to write cross-platform Node.js code
★ 1,421+0Star change over the last 7 days - #652
A free book about developing secure and robust systems software.
★ 1,413+0Star change over the last 7 days - #653★ 1,412+0Star change over the last 7 days
- #654
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
★ 1,408+0Star change over the last 7 days - #655
A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks.
★ 1,408+0Star change over the last 7 days - #656★ 1,399+0Star change over the last 7 days
- #657
Enhance the security and privacy of your Windows 10 and Windows 11 deployments with our fully optimized, hardened, and debloated script. Adhere to industry best practices and Department of Defense STIG/SRG requirements for optimal performance and security.
★ 1,388+0Star change over the last 7 days - #658
Home Assistant integration to manage Eufy Security devices as cameras, home base stations, doorbells, motion and contact sensors.
★ 1,387+0Star change over the last 7 days - #659
Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0
★ 1,386+0Star change over the last 7 days - #660
TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!
★ 1,383+0Star change over the last 7 days