Web exploit detectorThe Web Exploit Detector is a Node.js application used to detect possible infections, malicious code and suspicious files in web hosting environments
Pest🐞 Primitive Erlang Security Tool
NotrulerThe opposite of Ruler, provides blue teams with the ability to detect Ruler usage against Exchange.
Gscan本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。
PurifyAll-in-one tool for managing vulnerability reports from AppSec pipelines
IotsharkIotShark - Monitoring and Analyzing IoT Traffic
VulsAgent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
LynisLynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
ResourcesA Storehouse of resources related to Bug Bounty Hunting collected from different sources. Latest guides, tools, methodology, platforms tips, and tricks curated by us.
Audit scriptsScripts to gather system configuration information for offline/remote auditing
HoperSecurity tool to trace URL's jumps across the rel links to obtain the last URL
PytosA Python SDK for Tufin Orchestration Suite
Repo Security ScannerCLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys
MarsnakeSystem Optimizer and Monitoring, Security Auditing, Vulnerability scanner for Linux, macOS, and UNIX-based systems
Cs SuiteCloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
Sn0intSemi-automatic OSINT framework and package manager
OssaOpen-Source Security Architecture | 开源安全架构
Dsinternals Directory Services Internals (DSInternals) PowerShell Module and Framework
VhostscanA virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
Grauditgrep rough audit - source code auditing tool
BrakemanA static analysis security vulnerability scanner for Ruby on Rails applications
DiamorphineLKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64)
InqlInQL - A Burp Extension for GraphQL Security Testing
SqliscannerAutomatic SQL injection with Charles and sqlmap api
Jok3rJok3r v3 BETA 2 - Network and Web Pentest Automation Framework
DawnscannerDawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.
Skf FlaskSecurity Knowledge Framework (SKF) Python Flask / Angular project
Kube Scankube-scan: Octarine k8s cluster risk assessment tool
Npq🎖safely* install packages with npm or yarn by auditing them as part of your install process
KlarIntegration of Clair and Docker Registry
Dradis CeDradis Framework: Colllaboration and reporting for IT Security teams
NfcgateAn NFC research toolkit application for Android
0xsp Mongoosea unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and privilege escalations attacks, replicate the tactics and techniques of an advanced adversary in a network.
PwndocPentest Report Generator
OtsecaOpen source security auditing tool to search and dump system configuration. It allows you to generate reports in HTML or RAW-HTML formats.
HellraiserVulnerability scanner using Nmap for scanning and correlating found CPEs with CVEs.
ArchstrikeAn Arch Linux repository for security professionals and enthusiasts. Done the Arch Way and optimized for i686, x86_64, ARMv6, ARMv7 and ARMv8.
Advisory DbSecurity advisory database for Rust crates published through crates.io
Fwanalyzera tool to analyze filesystem images for security
SecuritymanageframworkSecurity Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management, account management, knowledge base management, security scanning automation function modules, and can be used for internal security management. This platform is designed to help Party A with fewer security personnel, complicated business lines, difficult periodic inspection and low automation to better achieve internal safety management.
W5Security Orchestration, Automation and Response (SOAR) Platform. 安全编排与自动化响应平台,无需编写代码的安全自动化,使用 SOAR 可以让团队工作更加高效
TaipanWeb application vulnerability scanner
Enum4linux NgA next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.
SuperSecure, Unified, Powerful and Extensible Rust Android Analyzer
Ssh Mitmssh mitm server for security audits supporting public key authentication, session hijacking and file manipulation
TlsfuzzerSSL and TLS protocol test suite and fuzzer