LynisLynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Stars: ✭ 9,137 (+966.16%)
VulsAgent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
Stars: ✭ 8,844 (+931.97%)
MarsnakeSystem Optimizer and Monitoring, Security Auditing, Vulnerability scanner for Linux, macOS, and UNIX-based systems
Stars: ✭ 16 (-98.13%)
CobraSource Code Security Audit (源代码安全审计)
Stars: ✭ 2,802 (+226.95%)
MinesweeperA Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).
Stars: ✭ 162 (-81.1%)
ElectriceyeContinuously monitor your AWS services for configurations that can lead to degradation of confidentiality, integrity or availability. All results will be sent to Security Hub for further aggregation and analysis.
Stars: ✭ 255 (-70.25%)
WsltoolsWeb Scan Lazy Tools - Python Package
Stars: ✭ 288 (-66.39%)
Btle SnifferPassively scan for Bluetooth Low Energy devices and attempt to fingerprint them
Stars: ✭ 87 (-89.85%)
SuperSecure, Unified, Powerful and Extensible Rust Android Analyzer
Stars: ✭ 340 (-60.33%)
Kube Scankube-scan: Octarine k8s cluster risk assessment tool
Stars: ✭ 566 (-33.96%)
ReconnoitreA security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
Stars: ✭ 1,824 (+112.84%)
RecsechRecsech is a tool for doing Footprinting and Reconnaissance on the target web. Recsech collects information such as DNS Information, Sub Domains, HoneySpot Detected, Subdomain takeovers, Reconnaissance On Github and much more you can see in Features in tools .
Stars: ✭ 173 (-79.81%)
esa-httpclientAn asynchronous event-driven HTTP client based on netty.
Stars: ✭ 82 (-90.43%)
InqlInQL - A Burp Extension for GraphQL Security Testing
Stars: ✭ 715 (-16.57%)
Audit scriptsScripts to gather system configuration information for offline/remote auditing
Stars: ✭ 55 (-93.58%)
TaipanWeb application vulnerability scanner
Stars: ✭ 359 (-58.11%)
W5Security Orchestration, Automation and Response (SOAR) Platform. 安全编排与自动化响应平台,无需编写代码的安全自动化,使用 SOAR 可以让团队工作更加高效
Stars: ✭ 367 (-57.18%)
OssaOpen-Source Security Architecture | 开源安全架构
Stars: ✭ 796 (-7.12%)
KraneKubernetes RBAC static Analysis & visualisation tool
Stars: ✭ 254 (-70.36%)
Awesome Http BenchmarkHTTP(S) benchmark tools, testing/debugging, & restAPI (RESTful)
Stars: ✭ 2,236 (+160.91%)
Ladon大型内网渗透扫描器&Cobalt Strike,Ladon8.9内置120个模块,包含信息收集/存活主机/端口扫描/服务识别/密码爆破/漏洞检测/漏洞利用。漏洞检测含MS17010/SMBGhost/Weblogic/ActiveMQ/Tomcat/Struts2,密码口令爆破(Mysql/Oracle/MSSQL)/FTP/SSH(Linux)/VNC/Windows(IPC/WMI/SMB/Netbios/LDAP/SmbHash/WmiHash/Winrm),远程执行命令(smbexec/wmiexe/psexec/atexec/sshexec/webshell),降权提权Runas、GetSystem,Poc/Exploit,支持Cobalt Strike 3.X-4.0
Stars: ✭ 2,911 (+239.67%)
Salt ScannerLinux vulnerability scanner based on Salt Open and Vulners audit API, with Slack notifications and JIRA integration
Stars: ✭ 261 (-69.54%)
ProwlerProwler is a security tool to perform AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It contains more than 200 controls covering CIS, ISO27001, GDPR, HIPAA, SOC2, ENS and other security frameworks.
Stars: ✭ 4,561 (+432.21%)
Ssh Mitmssh mitm server for security audits supporting public key authentication, session hijacking and file manipulation
Stars: ✭ 335 (-60.91%)
E2guardianE2guardian is a web content filter that can work in proxy, transparent or icap server modes
Stars: ✭ 340 (-60.33%)
IsahcThe practical HTTP client that is fun to use.
Stars: ✭ 338 (-60.56%)
Kurlykurly is an alternative to the widely popular curl program, written in Golang.
Stars: ✭ 319 (-62.78%)
Fwanalyzera tool to analyze filesystem images for security
Stars: ✭ 382 (-55.43%)
EchoHigh performance, minimalist Go web framework
Stars: ✭ 21,297 (+2385.06%)
A Red Teamer DiariesRedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
Stars: ✭ 382 (-55.43%)
PatrowlmanagerPatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform
Stars: ✭ 363 (-57.64%)
HellraiserVulnerability scanner using Nmap for scanning and correlating found CPEs with CVEs.
Stars: ✭ 413 (-51.81%)
Xss Listener🕷️ XSS Listener is a penetration tool for easy to steal data with various XSS.
Stars: ✭ 414 (-51.69%)
OtsecaOpen source security auditing tool to search and dump system configuration. It allows you to generate reports in HTML or RAW-HTML formats.
Stars: ✭ 416 (-51.46%)
Deimosc2DeimosC2 is a Golang command and control framework for post-exploitation.
Stars: ✭ 423 (-50.64%)
ArchstrikeAn Arch Linux repository for security professionals and enthusiasts. Done the Arch Way and optimized for i686, x86_64, ARMv6, ARMv7 and ARMv8.
Stars: ✭ 401 (-53.21%)
0xsp Mongoosea unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and privilege escalations attacks, replicate the tactics and techniques of an advanced adversary in a network.
Stars: ✭ 419 (-51.11%)
BurpaBurp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application Security Testing (DAST).
Stars: ✭ 427 (-50.18%)
SalusSecurity scanner coordinator
Stars: ✭ 441 (-48.54%)
Appinfoscanner一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
Stars: ✭ 424 (-50.53%)
Nginx AutoinstallCompile Nginx from source with custom modules on Debian and Ubuntu
Stars: ✭ 443 (-48.31%)
YasuoA ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network
Stars: ✭ 517 (-39.67%)
RaptorWeb-based Source Code Vulnerability Scanner
Stars: ✭ 314 (-63.36%)
ApplicationinspectorA source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.
Stars: ✭ 3,873 (+351.93%)
EvilscanNodeJS Simple Network Scanner
Stars: ✭ 428 (-50.06%)
TelegraphSecure Web Server for iOS, tvOS and macOS
Stars: ✭ 474 (-44.69%)
Npq🎖safely* install packages with npm or yarn by auditing them as part of your install process
Stars: ✭ 513 (-40.14%)
BlinksocksA framework for building composable proxy protocol stack.
Stars: ✭ 587 (-31.51%)
Skf FlaskSecurity Knowledge Framework (SKF) Python Flask / Angular project
Stars: ✭ 573 (-33.14%)
Fast Android Networking🚀 A Complete Fast Android Networking Library that also supports HTTP/2 🚀
Stars: ✭ 5,346 (+523.8%)
Cs SuiteCloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
Stars: ✭ 815 (-4.9%)
ChangemeA default credential scanner.
Stars: ✭ 928 (+8.28%)
Sn0intSemi-automatic OSINT framework and package manager
Stars: ✭ 814 (-5.02%)
HabuHacking Toolkit
Stars: ✭ 635 (-25.9%)
FarwestFramework for building RESTful HATEOAS-driven applications.
Stars: ✭ 18 (-97.9%)
HardeningHardening Ubuntu. Systemd edition.
Stars: ✭ 705 (-17.74%)