Skip to content
70

Awesome Security

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

15k stars2,414 forks267 entriesLast push Jan 11, 2026 (8 months ago)License MIT

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Network >Network architecture

Network-segmentation-cheat-sheet

This project was created to publish the best practices for segmentation of the corporate network of any company. In general, the schemes in this project are suitable for any company.

Network >Scanning / Pentesting

OpenVAS

OpenVAS is a framework of several services and tools offering a comprehensive and powerful vulnerability scanning and vulnerability management solution.

In 2 lists

Metasploit Framework

A tool for developing and executing exploit code against a remote target machine. Other important sub-projects include the Opcode Database, shellcode archive and related research.

In 7 listsDetails

Kali

Kali Linux is a Debian-derived Linux distribution designed for digital forensics and penetration testing. Kali Linux is preinstalled with numerous penetration-testing programs, including nmap (a port scanner), Wireshark (a packet analyzer), John the Ripper (a password cracker), and Aircrack-ng (a…

In 7 listsDetails

tsurugi

heavily customized Linux distribution that designed to support DFIR investigations, malware analysis and OSINT activities. It is based on Ubuntu 20.04(64-bit with a 5.15.12 custom kernel)

In 5 listsDetails

pig

A Linux packet crafting tool.

In 4 lists

scapy

Scapy: the python-based interactive packet manipulation program & library.

Pompem

Pompem is an open source tool, which is designed to automate the search for exploits in major databases. Developed in Python, has a system of advanced search, thus facilitating the work of pentesters and ethical hackers. In its current version, performs searches in databases: Exploit-db, 1337day,…

Nmap

Nmap is a free and open source utility for network discovery and security auditing.

In 10 listsDetails

Amass

Amass performs DNS subdomain enumeration by scraping the largest number of disparate data sources, recursive brute forcing, crawling of web archives, permuting and altering names, reverse DNS sweeping and other techniques.

In 4 listsDetails

Anevicon

The most powerful UDP-based load generator, written in Rust.

In 2 lists

Finshir

A coroutines-driven Low & Slow traffic generator, written in Rust.

Legion

Open source semi-automated discovery and reconnaissance network penetration testing framework.

In 3 lists

Lonkero

Enterprise-grade web vulnerability scanner with 60+ attack modules, built in Rust for penetration testing and security assessments.

In 4 listsDetails

Sublist3r

Fast subdomains enumeration tool for penetration testers

In 7 listsDetails

RustScan

Faster Nmap scanning with Rust. Take a 17 minute Nmap scan down to 19 seconds.

In 5 listsDetails

Boofuzz

Fuzzing engine and fuzz testing framework.

In 4 lists

monsoon

Very flexible and fast interactive HTTP enumeration/fuzzing.

In 2 lists

Netz

Discover internet-wide misconfigurations, using zgrab2 and others.

In 3 lists

Deepfence ThreatMapper

Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

In 6 listsDetails

Deepfence SecretScanner

Find secrets and passwords in container images and file systems.

In 3 lists

Cognito Scanner

CLI tool to pentest Cognito AWS instance. It implements three attacks: unwanted account creation, account oracle and identity pool escalation

Network >Monitoring / Logging

BoxyHQ

Open source API for security and compliance audit logging.

justniffer

Justniffer is a network protocol analyzer that captures network traffic and produces logs in a customized way, can emulate Apache web server log files, track response times and extract all "intercepted" files from the HTTP traffic.

httpry

httpry is a specialized packet sniffer designed for displaying and logging HTTP traffic. It is not intended to perform analysis itself, but to capture, parse, and log the traffic for later analysis. It can be run in real-time displaying the traffic as it is parsed, or as a daemon process that logs…

ngrep

ngrep strives to provide most of GNU grep's common features, applying them to the network layer. ngrep is a pcap-aware tool that will allow you to specify extended regular or hexadecimal expressions to match against data payloads of packets. It currently recognizes IPv4/6, TCP, UDP, ICMPv4/6, IGMP…

In 2 lists

passivedns

A tool to collect DNS records passively to aid Incident handling, Network Security Monitoring (NSM) and general digital forensics. PassiveDNS sniffs traffic from an interface or reads a pcap-file and outputs the DNS-server answers to a log file. PassiveDNS can cache/aggregate duplicate DNS answers…

In 3 lists

sagan

Sagan uses a 'Snort like' engine and rules to analyze logs (syslog/event log/snmptrap/netflow/etc).

ntopng

Ntopng is a network traffic probe that shows the network usage, similar to what the popular top Unix command does.

Fibratus

Fibratus is a tool for exploration and tracing of the Windows kernel. It is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very simple CLI which…

In 8 listsDetails

opensnitch

OpenSnitch is a GNU/Linux port of the Little Snitch application firewall

In 3 lists

wazuh

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of monitoring file system changes, system calls and inventory changes.

In 7 listsDetails

Matano

Open source serverless security lake platform on AWS that lets you ingest, store, and analyze petabytes of security data into an Apache Iceberg data lake and run realtime Python detections as code.

In 4 lists

Falco

The cloud-native runtime security project and de facto Kubernetes threat detection engine now part of the CNCF.

In 5 listsDetails

VAST

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

In 4 lists

Substation

Substation is a cloud native data pipeline and transformation toolkit written in Go.

In 5 listsDetails

Sigma2KQL

A repository of all SIGMA rules converted to KQL that runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository.

In 2 lists

Sigma2SPL

A repository of all SIGMA rules converted to SPL that runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository.

TerraSigma

A repository of all SIGMA rules converted to Microsoft Sentinel Terraform Scheduled analytic resources. The repository runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository. Proper entity mapping is completed for the rules to ensure…

In 2 lists

Network >IDS / IPS / Host IDS / Host IPS

Snort

Snort is a free and open source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS)created by Martin Roesch in 1998. Snort is now developed by Sourcefire, of which Roesch is the founder and CTO. In 2009, Snort entered InfoWorld's Open Source Hall of Fame as one…

In 9 listsDetails

Zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

In 6 listsDetails

zeek2es

An open source tool to convert Zeek logs to Elastic/OpenSearch. You can also output pure JSON from Zeek's TSV logs!

In 2 lists

DrKeithJones.com

A blog on cyber security and network security monitoring.

OSSEC

Comprehensive Open Source HIDS. Not for the faint of heart. Takes a bit to get your head around how it works. Performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. It runs on most operating systems, including Linux, MacOS,…

In 2 lists

Suricata

Suricata is a high performance Network IDS, IPS and Network Security Monitoring engine. Open Source and owned by a community run non-profit foundation, the Open Information Security Foundation (OISF). Suricata is developed by the OISF and its supporting vendors.

Security Onion

Security Onion is a Linux distro for intrusion detection, network security monitoring, and log management. It's based on Ubuntu and contains Snort, Suricata, Zeek, OSSEC, Sguil, Squert, Snorby, ELSA, Xplico, NetworkMiner, and many other security tools. The easy-to-use Setup wizard allows you to…

sshwatch

IPS for SSH similar to DenyHosts written in Python. It also can gather information about attacker during the attack in a log.

Stealth

File integrity checker that leaves virtually no sediment. Controller runs from another machine, which makes it hard for an attacker to know that the file system is being checked at defined pseudo random intervals over SSH. Highly recommended for small to medium deployments.

AIEngine

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua packet inspection engine with capabilities of learning without any human intervention, NIDS(Network Intrusion Detection System) functionality, DNS domain classification, network collector, network forensics and many others.

In 2 lists

Denyhosts

Thwart SSH dictionary based attacks and brute force attacks.

In 2 lists

Fail2Ban

Scans log files and takes action on IPs that show malicious behavior.

In 2 lists

SSHGuard

A software to protect services in addition to SSH, written in C

Lynis

an open source security auditing tool for Linux/Unix.

In 4 listsDetails

CrowdSec

CrowdSec is a free, modern & collaborative behavior detection engine, coupled with a global IP reputation network. It stacks on Fail2Ban's philosophy but is IPV6 compatible and 60x faster (Go vs Python), uses Grok patterns to parse logs and YAML scenario to identify behaviors. CrowdSec is…

In 6 listsDetails

wazuh

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of monitoring file system changes, system calls and inventory changes.

In 7 listsDetails

Network >Honey Pot / Honey Net

awesome-honeypots

The canonical awesome honeypot list.

In 5 listsDetails

HoneyPy

HoneyPy is a low to medium interaction honeypot. It is intended to be easy to: deploy, extend functionality with plugins, and apply custom configurations.

Conpot

ICS/SCADA Honeypot. Conpot is a low interactive server side Industrial Control Systems honeypot designed to be easy to deploy, modify and extend. By providing a range of common industrial control protocols we created the basics to build your own system, capable to emulate complex infrastructures…

Amun

Amun Python-based low-interaction Honeypot.

Glastopf

Glastopf is a Honeypot which emulates thousands of vulnerabilities to gather data from attacks targeting web applications. The principle behind it is very simple: Reply the correct response to the attacker exploiting the web application.

In 2 lists

Kippo

Kippo is a medium interaction SSH honeypot designed to log brute force attacks and, most importantly, the entire shell interaction performed by the attacker.

In 3 lists

Kojoney

Kojoney is a low level interaction honeypot that emulates an SSH server. The daemon is written in Python using the Twisted Conch libraries.

HonSSH

HonSSH is a high-interaction Honey Pot solution. HonSSH will sit between an attacker and a honey pot, creating two separate SSH connections between them.

Bifrozt

Bifrozt is a NAT device with a DHCP server that is usually deployed with one NIC connected directly to the Internet and one NIC connected to the internal network. What differentiates Bifrozt from other standard NAT devices is its ability to work as a transparent SSHv2 proxy between an attacker and…

HoneyDrive

HoneyDrive is the premier honeypot Linux distro. It is a virtual appliance (OVA) with Xubuntu Desktop 12.04.4 LTS edition installed. It contains over 10 pre-installed and pre-configured honeypot software packages such as Kippo SSH honeypot, Dionaea and Amun malware honeypots, Honeyd…

Cuckoo Sandbox

Cuckoo Sandbox is an Open Source software for automating analysis of suspicious files. To do so it makes use of custom components that monitor the behavior of the malicious processes while running in an isolated environment.

T-Pot Honeypot Distro

T-Pot is based on the network installer of Ubuntu Server 16/17.x LTS. The honeypot daemons as well as other support components being used have been containerized using docker. This allows us to run multiple honeypot daemons on the same network interface while maintaining a small footprint and…

Network >Full Packet Capture / Forensic

tcpflow

tcpflow is a program that captures data transmitted as part of TCP connections (flows), and stores the data in a way that is convenient for protocol analysis and debugging. Each TCP flow is stored in its own file. Thus, the typical TCP flow will be stored in two files, one for each direction.…

In 4 lists

Deepfence PacketStreamer

High-performance remote packet capture and collection tool, distributed tcpdump for cloud native environments.

In 4 lists

Xplico

The goal of Xplico is extract from an internet traffic capture the applications data contained. For example, from a pcap file Xplico extracts each email (POP, IMAP, and SMTP protocols), all HTTP contents, each VoIP call (SIP), FTP, TFTP, and so on. Xplico isn’t a network protocol analyzer. Xplico…

Moloch

Moloch is an open source, large scale IPv4 packet capturing (PCAP), indexing and database system. A simple web interface is provided for PCAP browsing, searching, and exporting. APIs are exposed that allow PCAP data and JSON-formatted session data to be downloaded directly. Simple security is…

In 3 lists

OpenFPC

OpenFPC is a set of tools that combine to provide a lightweight full-packet network traffic recorder & buffering system. It's design goal is to allow non-expert users to deploy a distributed network traffic recorder on COTS hardware while integrating into existing alert and log management tools.

Dshell

Dshell is a network forensic analysis framework. Enables rapid development of plugins to support the dissection of network packet captures.

In 4 lists

stenographer

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets.

In 5 listsDetails

Network >Sniffer

wireshark

Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Wireshark is very similar to tcpdump, but has a graphical front-end, plus some integrated sorting and filtering options.

In 20 listsDetails

netsniff-ng

netsniff-ng is a free Linux networking toolkit, a Swiss army knife for your daily Linux network plumbing if you will. Its gain of performance is reached by zero-copy mechanisms, so that on packet reception and transmission the kernel does not need to copy packets from kernel space to user space…

In 3 lists

Live HTTP headers

Live HTTP headers is a free firefox addon to see your browser requests in real time. It shows the entire headers of the requests and can be used to find the security loopholes in implementations.

Network >Security Information & Event Management

Prelude

Prelude is a Universal "Security Information & Event Management" (SIEM) system. Prelude collects, normalizes, sorts, aggregates, correlates and reports all security-related events independently of the product brand or license giving rise to such events; Prelude is "agentless".

In 3 lists

OSSIM

OSSIM provides all of the features that a security professional needs from a SIEM offering – event collection, normalization, and correlation.

In 3 lists

FIR

Fast Incident Response, a cybersecurity incident management platform.

In 5 listsDetails

LogESP

Open Source SIEM (Security Information and Event Management system).

wazuh

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of monitoring file system changes, system calls and inventory changes.

In 7 listsDetails

VAST

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

In 4 lists

Matano

Open source serverless security lake platform on AWS that lets you ingest, store, and analyze petabytes of security data into an Apache Iceberg data lake and run realtime Python detections as code.

In 4 lists

Network >VPN

OpenVPN

OpenVPN is an open source software application that implements virtual private network (VPN) techniques for creating secure point-to-point or site-to-site connections in routed or bridged configurations and remote access facilities. It uses a custom security protocol that utilizes SSL/TLS for key…

In 7 listsDetails

Firezone

Open-source VPN server and egress firewall for Linux built on WireGuard that makes it simple to manage secure remote access to your company’s private networks. Firezone is easy to set up (all dependencies are bundled thanks to Chef Omnibus), secure, performant, and self hostable.

In 5 listsDetails

TorForge

Advanced transparent Tor proxy with kernel-level iptables routing, post-quantum encryption (Kyber768), kill switch, steganography mode, and AI-powered circuit selection.

Network >Fast Packet Processing

DPDK

DPDK is a set of libraries and drivers for fast packet processing.

PFQ

PFQ is a functional networking framework designed for the Linux operating system that allows efficient packets capture/transmission (10G and beyond), in-kernel functional processing and packets steering across sockets/end-points.

PF_RING

PF_RING is a new type of network socket that dramatically improves the packet capture speed.

PF_RING ZC (Zero Copy)

PF_RING ZC (Zero Copy) is a flexible packet processing framework that allows you to achieve 1/10 Gbit line rate packet processing (both RX and TX) at any packet size. It implements zero copy operations including patterns for inter-process and inter-VM (KVM) communications.

PACKET_MMAP/TPACKET/AF_PACKET

It's fine to use PACKET_MMAP to improve the performance of the capture and transmission process in Linux.

netmap

netmap is a framework for high speed packet I/O. Together with its companion VALE software switch, it is implemented as a single kernel module and available for FreeBSD, Linux and now also Windows.

Network >Firewall

pfSense

Firewall and Router FreeBSD distribution.

In 9 listsDetails

OPNsense

is an open source, easy-to-use and easy-to-build FreeBSD based firewall and routing platform. OPNsense includes most of the features available in expensive commercial firewalls, and more in many cases. It brings the rich feature set of commercial offerings with the benefits of open and verifiable…

In 10 listsDetails

fwknop

Protects ports via Single Packet Authorization in your firewall.

In 4 lists

Network >Anti-Spam

Spam Scanner

Anti-Spam Scanning Service and Anti-Spam API by @niftylettuce.

rspamd

Fast, free and open-source spam filtering system.

In 3 lists

SpamAssassin

A powerful and popular email spam filter employing a variety of detection technique.

In 3 lists

Scammer-List

A free open source AI based Scam and Spam Finder with a free API

Endpoint >Anti-Virus / Anti-Malware

Fastfinder

Fast customisable cross-platform suspicious file finder. Supports md5/sha1/sha256 hashs, litteral/wildcard strings, regular expressions and YARA rules. Can easily be packed to be deployed on any windows / linux host.

In 3 lists

Linux Malware Detect

A malware scanner for Linux designed around the threats faced in shared hosted environments.

LOKI

Simple Indicators of Compromise and Incident Response Scanner

In 4 lists

rkhunter

A Rootkit Hunter for Linux

In 5 lists

ClamAv

ClamAV® is an open-source antivirus engine for detecting trojans, viruses, malware & other malicious threats.

In 2 lists

Endpoint >Content Disarm & Reconstruct

DocBleach

An open-source Content Disarm & Reconstruct software sanitizing Office, PDF and RTF Documents.

Endpoint >Configuration Management

Fleet device management

Fleet is the lightweight, programmable telemetry platform for servers and workstations. Get comprehensive, customizable data from all your devices and operating systems.

In 4 listsDetails

Rudder

Rudder is an easy to use, web-driven, role-based solution for IT Infrastructure Automation & Compliance. Automate common system administration tasks (installation, configuration); Enforce configuration over time (configuring once is good, ensuring that configuration is valid and automatically…

Endpoint >Authentication

google-authenticator

The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms, as well as a pluggable authentication module (PAM). One-time passcodes are generated using open standards developed by the Initiative for Open Authentication (OATH) (which is…

Stegcloak

Securely assign Digital Authenticity to any written text

In 8 listsDetails

Endpoint >Mobile / Android / iOS

android-security-awesome

A collection of android security related resources. A lot of work is happening in academia and industry on tools to perform dynamic analysis, static analysis and reverse engineering of android apps.

In 5 listsDetails

SecMobi Wiki

A collection of mobile security resources which including articles, blogs, books, groups, projects, tools and conferences. *

OWASP Mobile Security Testing Guide

A comprehensive manual for mobile app security testing and reverse engineering.

In 4 listsDetails

OSX Security Awesome

A collection of OSX and iOS security resources

In 2 lists

Themis

High-level multi-platform cryptographic framework for protecting sensitive data: secure messaging with forward secrecy and secure data storage (AES256GCM), suits for building end-to-end encrypted applications.

In 13 listsDetails

Mobile Security Wiki

A collection of mobile security resources.

Apktool

A tool for reverse engineering Android apk files.

In 3 lists

jadx

Command line and GUI tools for produce Java source code from Android Dex and Apk files.

In 8 listsDetails

enjarify

A tool for translating Dalvik bytecode to equivalent Java bytecode.

Android Storage Extractor

A tool to extract local data storage of an Android application in one click.

Quark-Engine

An Obfuscation-Neglect Android Malware Scoring System.

In 4 listsDetails

dotPeek

Free-of-charge standalone tool based on ReSharper's bundled decompiler.

In 3 lists

hardened_malloc

Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.

In 2 lists

AMExtractor

AMExtractor can dump out the physical content of your Android device even without kernel source code.

frida

Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.

In 4 lists

UDcide

Android Malware Behavior Editor.

reFlutter

Flutter Reverse Engineering Framework

Endpoint >Forensics

grr

GRR Rapid Response is an incident response framework focused on remote live forensics.

In 6 listsDetails

Volatility

Python based memory extraction and analysis framework.

In 8 listsDetails

mig

MIG is a platform to perform investigative surgery on remote endpoints. It enables investigators to obtain information from large numbers of systems in parallel, thus accelerating investigation of incidents and day-to-day operations security.

ir-rescue

ir-rescue is a Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

In 4 lists

Logdissect

CLI utility and Python API for analyzing log files and other data.

In 4 lists

Meerkat

PowerShell-based Windows artifact collection for threat hunting and incident response.

In 2 lists

Rekall

The Rekall Framework is a completely open collection of tools, implemented in Python under the Apache and GNU General Public License, for the extraction and analysis of digital artifacts computer systems.

In 3 lists

LiME

Linux Memory Extractor

In 4 lists

Maigret

Maigret collect a dossier on a person by username only, checking for accounts on a huge number of sites and gathering all the available information from web pages.

In 5 listsDetails

Threat Intelligence

abuse.ch

ZeuS Tracker / SpyEye Tracker / Palevo Tracker / Feodo Tracker tracks Command&Control servers (hosts) around the world and provides you a domain- and an IP-blocklist.

In 3 lists

Cyware Threat Intelligence Feeds

Cyware’s Threat Intelligence feeds brings to you the valuable threat data from a wide range of open and trusted sources to deliver a consolidated stream of valuable and actionable threat intelligence. Our threat intel feeds are fully compatible with STIX 1.x and 2.0, giving you the latest…

Emerging Threats - Open Source

Emerging Threats began 10 years ago as an open source community for collecting Suricata and SNORT® rules, firewall rules, and other IDS rulesets. The open source community still plays an active role in Internet security, with more than 200,000 active users downloading the ruleset daily. The ETOpen…

PhishTank

PhishTank is a collaborative clearing house for data and information about phishing on the Internet. Also, PhishTank provides an open API for developers and researchers to integrate anti-phishing data into their applications at no charge.

SBL / XBL / PBL / DBL / DROP / ROKSO

The Spamhaus Project is an international nonprofit organization whose mission is to track the Internet's spam operations and sources, to provide dependable realtime anti-spam protection for Internet networks, to work with Law Enforcement Agencies to identify and pursue spam and malware gangs…

Internet Storm Center

The ISC was created in 2001 following the successful detection, analysis, and widespread warning of the Li0n worm. Today, the ISC provides a free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back…

AutoShun

AutoShun is a Snort plugin that allows you to send your Snort IDS logs to a centralized server that will correlate attacks from your sensor logs with other snort sensors, honeypots, and mail filters from around the world.

In 2 lists

DNS-BH

The DNS-BH project creates and maintains a listing of domains that are known to be used to propagate malware and spyware. This project creates the Bind and Windows zone files required to serve fake replies to localhost for any requests to these, thus preventing many spyware installs and reporting.

AlienVault Open Threat Exchange

AlienVault Open Threat Exchange (OTX), to help you secure your networks from data loss, service disruption and system compromise caused by malicious IP addresses.

Tor Bulk Exit List

CollecTor, your friendly data-collecting service in the Tor network. CollecTor fetches data from various nodes and services in the public Tor network and makes it available to the world. If you're doing research on the Tor network, or if you're developing an application that uses Tor network data,…

leakedin.com

The primary purpose of leakedin.com is to make visitors aware about the risks of loosing data. This blog just compiles samples of data lost or disclosed on sites like pastebin.com.

FireEye OpenIOCs

FireEye Publicly Shared Indicators of Compromise (IOCs)

In 2 lists

OpenVAS NVT Feed

The public feed of Network Vulnerability Tests (NVTs). It contains more than 35,000 NVTs (as of April 2014), growing on a daily basis. This feed is configured as the default for OpenVAS.

Project Honey Pot

Project Honey Pot is the first and only distributed system for identifying spammers and the spambots they use to scrape addresses from your website. Using the Project Honey Pot system you can install addresses that are custom-tagged to the time and IP address of a visitor to your site. If one of…

virustotal

VirusTotal, a subsidiary of Google, is a free online service that analyzes files and URLs enabling the identification of viruses, worms, trojans and other kinds of malicious content detected by antivirus engines and website scanners. At the same time, it may be used as a means to detect false…

In 13 listsDetails

IntelMQ

IntelMQ is a solution for CERTs for collecting and processing security feeds, pastebins, tweets using a message queue protocol. It's a community driven initiative called IHAP (Incident Handling Automation Project) which was conceptually designed by European CERTs during several InfoSec events. Its…

In 2 lists

CIFv2

CIF is a cyber threat intelligence management system. CIF allows you to combine known malicious threat information from many sources and use that information for identification (incident response), detection (IDS) and mitigation (null route).

In 2 lists

MISP - Open Source Threat Intelligence Platform

MISP threat sharing platform is a free and open source software helping information sharing of threat intelligence including cyber security indicators. A threat intelligence platform for gathering, sharing, storing and correlating Indicators of Compromise of targeted attacks, threat intelligence,…

In 5 listsDetails

PhishStats

Phishing Statistics with search for IP, domain and website title.

In 3 lists

Threat Jammer

REST API service that allows developers, security engineers, and other IT professionals to access curated threat intelligence data from a variety of sources.

Cyberowl

A daily updated summary of the most frequent types of security incidents currently being reported from different sources.

Social Engineering

Gophish

An Open-Source Phishing Framework.

In 5 listsDetails

Web >Organization

OWASP

The Open Web Application Security Project (OWASP) is a 501(c)(3) worldwide not-for-profit charitable organization focused on improving the security of software.

Portswigger

PortSwigger offers tools for web application security, testing & scanning. Choose from a wide range of security tools & identify the very latest vulnerabilities.

Web >Web Application Firewall

ModSecurity

ModSecurity is a toolkit for real-time web application monitoring, logging, and access control.

BunkerWeb

BunkerWeb is a full-featured open-source web server with ModeSecurity WAF, HTTPS with transparent Let's Encrypt renewal, automatic ban of strange behaviors based on HTTP codes, bot and bad IPs block, connection limits, state-of-the-art security presets, Web UI and much more.

In 7 listsDetails

NAXSI

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX, NAXSI means Nginx Anti Xss & Sql Injection.

In 2 lists

sql_firewall

SQL Firewall Extension for PostgreSQL

ironbee

IronBee is an open source project to build a universal web application security sensor. IronBee as a framework for developing a system for securing web applications - a framework for building a web application firewall (WAF).

Curiefense

Curiefense adds a broad set of automated web security tools, including a WAF to Envoy Proxy.

In 2 lists

open-appsec

open-appsec is an open source machine-learning security engine that preemptively and automatically prevents threats against Web Application & APIs.

Web >Scanning / Pentesting

Spyse

Spyse is an OSINT search engine that provides fresh data about the entire web. All the data is stored in its own DB for instant access and interconnected with each other for flexible search. Provided data: IPv4 hosts, sub/domains/whois, ports/banners/protocols, technologies, OS, AS, wide SSL/TLS…

In 5 listsDetails

sqlmap

sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting…

In 3 lists

ZAP

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration…

In 2 lists

OWASP Testing Checklist v4

List of some controls to test during a web vulnerability assessment. Markdown version may be found here.

w3af

w3af is a Web Application Attack and Audit Framework. The project’s goal is to create a framework to help you secure your web applications by finding and exploiting all web application vulnerabilities.

Recon-ng

Recon-ng is a full-featured Web Reconnaissance framework written in Python. Recon-ng has a look and feel similar to the Metasploit Framework.

In 6 listsDetails

PTF

The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.

In 2 lists

Infection Monkey

A semi automatic pen testing tool for mapping/pen-testing networks. Simulates a human attacker.

In 2 lists

ACSTIS

ACSTIS helps you to scan certain web applications for AngularJS Client-Side Template Injection (sometimes referred to as CSTI, sandbox escape or sandbox bypass). It supports scanning a single request but also crawling the entire web application for the AngularJS CSTI vulnerability.

In 2 lists

padding-oracle-attacker

padding-oracle-attacker is a CLI tool and library to execute padding oracle attacks (which decrypts data encrypted in CBC mode) easily, with support for concurrent network requests and an elegant UI.

In 2 lists

is-website-vulnerable

finds publicly known security vulnerabilities in a website's frontend JavaScript libraries.

In 2 lists

PhpSploit

Full-featured C2 framework which silently persists on webserver via evil PHP oneliner. Built for stealth persistence, with many privilege-escalation & post-exploitation features.

In 4 listsDetails

Keyscope

Keyscope is an extensible key and secret validation for checking active secrets against multiple SaaS vendors built in Rust

In 4 lists

Cyclops

The Cyclops is a web browser with XSS detection feature, it is chromium-based xss detection that used to find the flows from a source to a sink.

Scanmycode CE (Community Edition)

Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners with One Report. Currently supports: PHP, Java, Scala, Python, Ruby, Javascript, GO, Secret Scanning, Dependency Confusion, Trojan Source, Open Source and Proprietary Checks (total ca. 1000 checks)

recon

a fast Rust based CLI that uses SQL to query over files, code, or malware with content classification and processing for security experts

CakeFuzzer

The ultimate web application security testing tool for CakePHP-based web applications. CakeFuzzer employs a predefined set of attacks that are randomly modified before execution. Leveraging its deep understanding of the Cake PHP framework, Cake Fuzzer launches attacks on all potential application…

Artemis

A modular vulnerability scanner with automatic report generation capabilities.

Trust Scan

URL security scanner with WHOIS, SSL, threat intelligence (URLhaus, PhishTank, Spamhaus), and 40+ scam/phishing pattern detection. Includes optional AI analysis via Ollama. (Demo)

In 2 lists

react2shell-scanner

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Scans React 19.x and Next.js projects for critical remote code execution flaws.

shai-hulud-scanner

Detect indicators of compromise from the Shai Hulud 2.0 npm supply chain attack that compromised 796+ packages. Performs comprehensive security checks for malicious files, hashes, and patterns.

Web >Runtime Application Self-Protection

Sqreen

Sqreen is a Runtime Application Self-Protection (RASP) solution for software teams. An in-app agent instruments and monitors the app. Suspicious user activities are reported and attacks are blocked at runtime without code modification or traffic redirection.

In 2 lists

OpenRASP

An open source RASP solution actively maintained by Baidu Inc. With context-aware detection algorithm the project achieved nearly no false positives. And less than 3% performance reduction is observed under heavy server load.

In 3 lists

Web >Development

API Security in Action

Book covering API security including secure development, token-based authentication, JSON Web Tokens, OAuth 2, and Macaroons. (early access, published continuously, final release summer 2020)

Secure by Design

Book that identifies design patterns and coding styles that make lots of security vulnerabilities less likely. (early access, published continuously, final release fall 2017)

In 2 lists

Understanding API Security

Free eBook sampler that gives some context for how API security works in the real world by showing how APIs are put together and how the OAuth protocol can be used to protect them.

OAuth 2 in Action

Book that teaches you practical use and deployment of OAuth 2 from the perspectives of a client, an authorization server, and a resource server.

OWASP ZAP Node API

Leverage the OWASP Zed Attack Proxy (ZAP) within your NodeJS applications with this official API.

GuardRails

A GitHub App that provides security feedback in Pull Requests.

In 4 listsDetails

Bearer

Scan code for security risks and vulnerabilities leading to sensitive data exposures.

In 6 listsDetails

Checkov

A static analysis tool for infrastucture as code (Terraform).

In 7 listsDetails

TFSec

A static analysis tool for infrastucture as code (Terraform).

In 2 lists

KICS

Scans IaC projects for security vulnerabilities, compliance issues, and infrastructure misconfiguration. Currently working with Terraform projects, Kubernetes manifests, Dockerfiles, AWS CloudFormation Templates, and Ansible playbooks.

In 5 listsDetails

Insider CLI

A open source Static Application Security Testing tool (SAST) written in GoLang for Java (Maven and Android), Kotlin (Android), Swift (iOS), .NET Full Framework, C# and Javascript (Node.js).

In 2 lists

Full Stack Python Security

A comprehensive look at cybersecurity for Python developers

In 2 lists

Making Sense of Cyber Security

A jargon-free, practical guide to the key concepts, terminology, and technologies of cybersecurity perfect for anyone planning or implementing a security strategy. (early access, published continuously, final release early 2022)

Security Checklist by OWASP

A checklist by OWASP for testing web applications based on assurance level. Covers multiple topics like Architecture, IAM, Sanitization, Cryptography and Secure Configuration.

In 2 lists

Pompelmi

Node.js file-upload malware scanner with MIME sniffing, ZIP-bomb protection and optional YARA rules.

In 5 listsDetails

Exploits & Payloads

PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

In 12 listsDetails

Red Team Infrastructure Deployment

Redcloud

A automated Red Team Infrastructure deployement using Docker.

Axiom

Axiom is a dynamic infrastructure framework to efficiently work with multi-cloud environments, build and deploy repeatable infrastructure focussed on offensive and defensive security.

Blue Team Infrastructure Deployment

MutableSecurity

CLI program for automating the setup, configuration, and use of cybersecurity solutions.

In 2 lists

Usability

Usable Security Course

Usable Security course at coursera. Quite good for those looking for how security and usability intersects.

Big Data

data_hacking

Examples of using IPython, Pandas, and Scikit Learn to get the most out of your security data.

hadoop-pcap

Hadoop library to read packet capture (PCAP) files.

In 2 lists

Workbench

A scalable python framework for security research and development teams.

OpenSOC

OpenSOC integrates a variety of open source big data technologies in order to offer a centralized tool for security monitoring and analysis.

Apache Metron (incubating)

Metron integrates a variety of open source big data technologies in order to offer a centralized tool for security monitoring and analysis.

Apache Spot (incubating)

Apache Spot is open source software for leveraging insights from flow and packet analysis.

binarypig

Scalable Binary Data Extraction in Hadoop. Malware Processing and Analytics over Pig, Exploration through Django, Twitter Bootstrap, and Elasticsearch.

Matano

Open source serverless security lake platform on AWS that lets you ingest, store, and analyze petabytes of security data into an Apache Iceberg data lake and run realtime Python detections as code.

In 4 lists

VAST

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

In 4 lists

DevOps

Securing DevOps

A book on Security techniques for DevOps that reviews state of the art practices used in securing web applications and their infrastructure.

In 2 lists

ansible-os-hardening

Ansible role for OS hardening

Trivy

A simple and comprehensive vulnerability scanner for containers and other artifacts, suitable for CI.

In 9 listsDetails

Preflight

helps you verify scripts and executables to mitigate supply chain attacks in your CI and other systems.

In 2 lists

Teller

a secrets management tool for devops and developers - manage secrets across multiple vaults and keystores from a single place.

In 2 lists

cve-ape

A non-intrusive CVE scanner for embedding in test and CI environments that can scan package lists and individual packages for existing CVEs via locally stored CVE database. Can also be used as an offline CVE scanner for e.g. OT/ICS.

Selefra

An open-source policy-as-code software that provides analytics for multi-cloud and SaaS.

In 4 listsDetails

Terminal

shellfirm

It is a handy utility to help avoid running dangerous commands with an extra approval step. You will immediately get a small prompt challenge that will double verify your action when risky patterns are detected.

In 2 lists

shellclear

It helps you to Secure your shell history commands by finding sensitive commands in your all history commands and allowing you to clean them.

Operating Systems >Privacy & Security

Qubes OS

Qubes OS is a free and open-source security-oriented operating system meant for single-user desktop computing.

In 9 listsDetails

Whonix

Operating System designed for anonymity.

In 4 listsDetails

Tails OS

Tails is a portable operating system that protects against surveillance and censorship.

In 8 listsDetails

Operating Systems >Online resources

Security related Operating Systems @ Rawsec

Complete list of security related operating systems

In 2 lists

Best Linux Penetration Testing Distributions @ CyberPunk

Description of main penetration testing distributions

Security @ Distrowatch

Website dedicated to talking about, reviewing and keeping up to date with open source operating systems

In 2 lists

Hardening Windows 10

Guide for hardening Windows 10

Datastores

databunker

Databunker is an address book on steroids for storing personal data. GDPR and encryption are out of the box.

In 3 lists

acra

Database security suite: proxy for data protection with transparent "on the fly" data encryption, data masking and tokenization, SQL firewall (SQL injections prevention), intrusion detection system.

In 6 listsDetails

blackbox

Safely store secrets in a VCS repo using GPG

In 8 listsDetails

confidant

Stores secrets in AWS DynamoDB, encrypted at rest and integrates with IAM

In 2 lists

dotgpg

A tool for backing up and versioning your production secrets or shared passwords securely and easily.

redoctober

Server for two-man rule style file encryption and decryption.

aws-vault

Store AWS credentials in the OSX Keychain or an encrypted file

In 4 lists

credstash

Store secrets using AWS KMS and DynamoDB

In 2 lists

chamber

Store secrets using AWS KMS and SSM Parameter Store

Safe

A Vault CLI that makes reading from and writing to the Vault easier to do.

Sops

An editor of encrypted files that supports YAML, JSON and BINARY formats and encrypts with AWS KMS and PGP.

In 6 listsDetails

passbolt

The password manager your team was waiting for. Free, open source, extensible, based on OpenPGP.

In 9 listsDetails

passpie

Multiplatform command-line password manager

Vault

An encrypted datastore secure enough to hold environment and application secrets.

In 6 listsDetails

LunaSec

Database for PII with automatic encryption/tokenization, sandboxed components for handling data, and centralized authorization controls.

In 2 lists

Fraud prevention

FingerprintJS

Identifies browser and hybrid mobile application users even when they purge data storage. Allows you to detect account takeovers, account sharing and repeated malicious activity.

In 2 lists

FingerprintJS Android

Identifies Android application users even when they purge data storage. Allows you to detect account takeovers, account sharing and repeated malicious activity.

EBooks

Holistic Info-Sec for Web Developers

Free and downloadable book series with very broad and deep coverage of what Web Developers and DevOps Engineers need to know in order to create robust, reliable, maintainable and secure software, networks and other, that are delivered continuously, on time, with no nasty surprises

Docker Security - Quick Reference: For DevOps Engineers

A book on understanding the Docker security defaults, how to improve them (theory and practical), along with many tools and techniques.

In 2 lists

How to Hack Like a Pornstar

A step by step process for breaking into a BANK, Sparc Flow, 2017

How to Hack Like a Legend

A hacker’s tale breaking into a secretive offshore company, Sparc Flow, 2018

How to Investigate Like a Rockstar

Live a real crisis to master the secrets of forensic analysis, Sparc Flow, 2017

Real World Cryptography

This early-access book teaches you applied cryptographic techniques to understand and apply security at every level of your systems and applications.

In 3 lists

AWS Security

This early-access book covers commong AWS security issues and best practices for access policies, data protection, auditing, continuous monitoring, and incident response.

In 2 lists

The Art of Network Penetration Testing

Book that is a hands-on guide to running your own penetration test on an enterprise network. (early access, published continuously, final release December 2020)

In 2 lists

Spring Boot in Practice

Book that is a practical guide which presents dozens of relevant scenarios in a convenient problem-solution-discussion format.. (early access, published continuously, final release fall 2021)

In 3 lists

Self-Sovereign Identity

A book about how SSI empowers us to receive digitally-signed credentials, store them in private wallets, and securely prove our online identities. (early access, published continuously, final release fall 2021)

In 2 lists

Data Privacy

A book that teaches you to implement technical privacy solutions and tools at scale. (early access, published continuously, final release January 2022)

Cyber Security Career Guide

Kickstart a career in cyber security by learning how to adapt your existing technical and non-technical skills. (early access, published continuously, final release Summer 2022)

Secret Key Cryptography

A book about cryptographic techniques and Secret Key methods. (early access, published continuously, final release Summer 2022)

In 2 lists

The Security Engineer Handbook

A short read that discusses the dos and dont's of working in a security team, and the many tricks and tips that can help you in your day-to-day as a security engineer.

Cyber Threat Hunting

Practical guide to cyber threat hunting.

Edge Computing Technology and Applications

A book about the business and technical foundation you need to create your edge computing strategy.

Spring Security in Action, Second Edition

A book about designing and developing Spring applications that are secure right from the start.

Azure Security

A practical guide to the native security services of Microsoft Azure.

In 2 lists

Node.js Secure Coding: Defending Against Command Injection Vulnerabilities

Learn secure coding conventions in Node.js by executing command injection attacks on real-world npm packages and analyzing vulnerable code.

Node.js Secure Coding: Prevention and Exploitation of Path Traversal Vulnerabilities

Master secure coding in Node.js with real-world vulnerable dependencies and experience firsthand secure coding techniques against Path Traversal vulnerabilities.

In 2 lists

Grokking Web Application Security

A book about building web apps that are ready for and resilient to any attack.

In 2 lists
See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed yesterday
91

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k574 entriesPushed today
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago