Project Awesome project awesome

Security

Collection 14.2k stars GitHub

Network

Scanning / Pentesting

Metasploit Framework

A tool for developing and executing exploit code against a remote target machine. Other important sub-projects include the Opcode Database, shellcode archive and related research.

pig 472 updated 5y ago

A Linux packet crafting tool.

scapy 335 updated 9mo ago

Scapy: the python-based interactive packet manipulation program & library.

Pompem 1.0k updated 3y ago

Pompem is an open source tool, which is designed to automate the search for exploits in major databases. Developed in Python, has a system of advanced search, thus facilitating the work of pentesters and ethical hackers. In its current version, performs searches in databases: Exploit-db, 1337day, Packetstorm Security...

Amass

Amass performs DNS subdomain enumeration by scraping the largest number of disparate data sources, recursive brute forcing, crawling of web archives, permuting and altering names, reverse DNS sweeping and other techniques.

Anevicon

The most powerful UDP-based load generator, written in Rust.

Finshir 33 updated 6y ago

A coroutines-driven Low & Slow traffic generator, written in Rust.

Legion 1.1k (archived)

Open source semi-automated discovery and reconnaissance network penetration testing framework.

Lonkero 821 updated 2d ago

Enterprise-grade web vulnerability scanner with 60+ attack modules, built in Rust for penetration testing and security assessments.

Sublist3r 10.9k updated 1y ago

Fast subdomains enumeration tool for penetration testers

RustScan 19.5k updated yesterday

Faster Nmap scanning with Rust. Take a 17 minute Nmap scan down to 19 seconds.

Boofuzz 2.3k updated 2d ago

Fuzzing engine and fuzz testing framework.

monsoon 495 updated 11mo ago

Very flexible and fast interactive HTTP enumeration/fuzzing.

Netz 399 updated 4y ago

Discover internet-wide misconfigurations, using zgrab2 and others.

Deepfence ThreatMapper 5.2k updated 17d ago

Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

Deepfence SecretScanner 3.3k updated 18d ago

Find secrets and passwords in container images and file systems.

Cognito Scanner 110 updated 2y ago

CLI tool to pentest Cognito AWS instance. It implements three attacks: unwanted account creation, account oracle and identity pool escalation

Monitoring / Logging

BoxyHQ 437 updated 2mo ago

Open source API for security and compliance audit logging.

passivedns 1.7k updated 1y ago

A tool to collect DNS records passively to aid Incident handling, Network Security Monitoring (NSM) and general digital forensics. PassiveDNS sniffs traffic from an interface or reads a pcap-file and outputs the DNS-server answers to a log file. PassiveDNS can cache/aggregate duplicate DNS answers in-memory, limiting the amount of data in the logfile without loosing the essens in the DNS answer.

Fibratus

Fibratus is a tool for exploration and tracing of the Windows kernel. It is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very simple CLI which encapsulates the machinery to start the kernel event stream collector, set kernel event filters or run the lightweight Python modules called filaments.

opensnitch 13.0k updated 14d ago

OpenSnitch is a GNU/Linux port of the Little Snitch application firewall

Substation 393 updated 2mo ago

Substation is a cloud native data pipeline and transformation toolkit written in Go.

Sigma2KQL 1 updated 3d ago

A repository of all SIGMA rules converted to KQL that runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository.

Sigma2SPL updated 3d ago

A repository of all SIGMA rules converted to SPL that runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository.

TerraSigma 2 updated 3d ago

A repository of all SIGMA rules converted to Microsoft Sentinel Terraform Scheduled analytic resources. The repository runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository. Proper entity mapping is completed for the rules to ensure the repo is plug-and-play.

Full Packet Capture / Forensic

tcpflow 1.8k updated 1mo ago

tcpflow is a program that captures data transmitted as part of TCP connections (flows), and stores the data in a way that is convenient for protocol analysis and debugging. Each TCP flow is stored in its own file. Thus, the typical TCP flow will be stored in two files, one for each direction. tcpflow can also process stored 'tcpdump' packet flows.

Deepfence PacketStreamer 1.9k (archived)

High-performance remote packet capture and collection tool, distributed tcpdump for cloud native environments.

Moloch 7.3k updated yesterday

Moloch is an open source, large scale IPv4 packet capturing (PCAP), indexing and database system. A simple web interface is provided for PCAP browsing, searching, and exporting. APIs are exposed that allow PCAP data and JSON-formatted session data to be downloaded directly. Simple security is implemented by using HTTPS and HTTP digest password support or by using apache in front. Moloch is not meant to replace IDS engines but instead work along side them to store and index all the network traffic in standard PCAP format, providing fast access. Moloch is built to be deployed across many systems and can scale to handle multiple gigabits/sec of traffic.

Dshell 5.5k updated 1y ago

Dshell is a network forensic analysis framework. Enables rapid development of plugins to support the dissection of network packet captures.

stenographer 1.8k (archived)

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets.

Other Security Awesome Lists

Other Security Awesome Lists

Awesome Honeypots 10.2k updated 11mo ago

An awesome list of honeypot resources.

Android Security Awesome 9.3k updated today

A collection of android security related resources.

Awesome ARM Exploitation

A curated list of ARM exploitation resources.

Awesome CTF

A curated list of CTF frameworks, libraries, resources and software.

Awesome Cyber Skills 4.3k updated 1y ago

A curated list of hacking environments where you can train your cyber skills legally and safely.

Awesome Personal Security 21.0k updated 25d ago

A curated list of digital security and privacy tips, with links to further resources.

Awesome Hacking 16.0k updated 1y ago

A curated list of awesome Hacking tutorials, tools and resources.

Awesome Malware Analysis

A curated list of awesome malware analysis tools and resources.

Awesome Security Newsletters 1.3k updated 1mo ago

A curated list of awesome newsletters to keep up to date on security news via e-mail.

Awesome PCAP Tools 3.4k updated 6mo ago

A collection of tools developed by other researchers in the Computer Science area to process network traces.

Awesome Pentest 25.6k updated 1mo ago

A collection of awesome penetration testing resources, tools and other shiny things.

Awesome Privacy

A curated list of privacy-respecting software and services.

Awesome Linux Containers 2.0k updated 1y ago

A curated list of awesome Linux Containers frameworks, libraries and software.

Awesome Incident Response 8.9k updated 1y ago

A curated list of resources for incident response.

Awesome Web Hacking 6.8k updated 26d ago

This list is for anyone wishing to learn about web application security but do not have a starting point.

Awesome Electron.js Hacking 661 updated 10mo ago

A curated list of awesome resources about Electron.js (in)security

Awesome Threat Intelligence 10.0k updated 2mo ago

A curated list of threat intelligence resources.

Awesome Threat Modeling 147 updated 1y ago

A curated list of Threat Modeling resources.

Awesome Pentest Cheat Sheets 4.3k (archived)

Collection of the cheat sheets useful for pentesting

Awesome Industrial Control System Security 32 updated 9y ago

A curated list of resources related to Industrial Control System (ICS) security.

Awesome YARA 4.2k updated 9d ago

A curated list of awesome YARA rules, tools, and people.

Awesome Threat Detection and Hunting 4.5k updated 2mo ago

A curated list of awesome threat detection and hunting resources.

Awesome Container Security

A curated list of awesome resources related to container building and runtime security

Awesome Crypto Papers 2.0k updated 1y ago

A curated list of cryptography papers, articles, tutorials and howtos.

Awesome Shodan Search Queries 7.3k updated 1y ago

A collection of interesting, funny, and depressing search queries to plug into Shodan.io.

Awesome Censys Queries 1.2k updated 16d ago

A collection of fascinating and bizarre Censys Search Queries.

Awesome Anti Forensics 984 updated 2y ago

A collection of awesome tools used to counter forensics activities.

Awesome Security Talks & Videos 4.2k updated 1mo ago

A curated list of awesome security talks, organized by year and then conference.

Awesome Bluetooth Security 599 updated 5mo ago

A curated list of Bluetooth security resources.

Awesome WebSocket Security

A curated list of WebSocket security resources.

Security Acronyms 43 updated 2mo ago

A curated list of security related acronyms and concepts

Awesome SOAR 983 updated 1y ago

A curated Cyber "Security Orchestration, Automation and Response (SOAR)" resources list.

Awesome Security Hardening 6.2k updated 5d ago

A collection of awesome security hardening guides, best practices, checklists, benchmarks, tools and other resources.

Endpoint

Mobile / Android / iOS

OWASP Mobile Security Testing Guide 12.8k updated 2d ago

A comprehensive manual for mobile app security testing and reverse engineering.

OSX Security Awesome 778 updated yesterday

A collection of OSX and iOS security resources

Themis 2.0k updated 2mo ago

High-level multi-platform cryptographic framework for protecting sensitive data: secure messaging with forward secrecy and secure data storage (AES256GCM), suits for building end-to-end encrypted applications.

Apktool 24.1k updated 2d ago

A tool for reverse engineering Android apk files.

jadx 47.8k updated yesterday

Command line and GUI tools for produce Java source code from Android Dex and Apk files.

enjarify

A tool for translating Dalvik bytecode to equivalent Java bytecode.

Android Storage Extractor 20 updated 7y ago

A tool to extract local data storage of an Android application in one click.

Quark-Engine 1.7k updated 2d ago

An Obfuscation-Neglect Android Malware Scoring System.

hardened_malloc 1.8k updated 5d ago

Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.

AMExtractor 14 updated 10y ago

AMExtractor can dump out the physical content of your Android device even without kernel source code.

frida 20.1k updated yesterday

Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.

UDcide

Android Malware Behavior Editor.

reFlutter 1.4k (archived)

Flutter Reverse Engineering Framework

Web

Scanning / Pentesting

Recon-ng 5.5k updated 1y ago

Recon-ng is a full-featured Web Reconnaissance framework written in Python. Recon-ng has a look and feel similar to the Metasploit Framework.

PTF 5.5k updated 1y ago

The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.

Infection Monkey 7.0k updated 10mo ago

A semi automatic pen testing tool for mapping/pen-testing networks. Simulates a human attacker.

ACSTIS 325 updated 4y ago

ACSTIS helps you to scan certain web applications for AngularJS Client-Side Template Injection (sometimes referred to as CSTI, sandbox escape or sandbox bypass). It supports scanning a single request but also crawling the entire web application for the AngularJS CSTI vulnerability.

padding-oracle-attacker 217 updated 3y ago

padding-oracle-attacker is a CLI tool and library to execute padding oracle attacks (which decrypts data encrypted in CBC mode) easily, with support for concurrent network requests and an elegant UI.

is-website-vulnerable 2.0k updated 6mo ago

finds publicly known security vulnerabilities in a website's frontend JavaScript libraries.

PhpSploit 2.4k updated 1y ago

Full-featured C2 framework which silently persists on webserver via evil PHP oneliner. Built for stealth persistence, with many privilege-escalation & post-exploitation features.

Keyscope 411 updated 8mo ago

Keyscope is an extensible key and secret validation for checking active secrets against multiple SaaS vendors built in Rust

Cyclops 126 updated 1y ago

The Cyclops is a web browser with XSS detection feature, it is chromium-based xss detection that used to find the flows from a source to a sink.

Scanmycode CE (Community Edition)

Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners with One Report. Currently supports: PHP, Java, Scala, Python, Ruby, Javascript, GO, Secret Scanning, Dependency Confusion, Trojan Source, Open Source and Proprietary Checks (total ca. 1000 checks)

recon

a fast Rust based CLI that uses SQL to query over files, code, or malware with content classification and processing for security experts

CakeFuzzer 105 updated 8mo ago

The ultimate web application security testing tool for CakePHP-based web applications. CakeFuzzer employs a predefined set of attacks that are randomly modified before execution. Leveraging its deep understanding of the Cake PHP framework, Cake Fuzzer launches attacks on all potential application entry points.

Trust Scan 2 updated 28d ago

URL security scanner with WHOIS, SSL, threat intelligence (URLhaus, PhishTank, Spamhaus), and 40+ scam/phishing pattern detection. Includes optional AI analysis via Ollama. (Demo)

react2shell-scanner 2 updated 2mo ago

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Scans React 19.x and Next.js projects for critical remote code execution flaws.

shai-hulud-scanner 2 updated 2mo ago

Detect indicators of compromise from the Shai Hulud 2.0 npm supply chain attack that compromised 796+ packages. Performs comprehensive security checks for malicious files, hashes, and patterns.

Artemis

A modular vulnerability scanner with automatic report generation capabilities.