security-headers
. Zero-dependency Node.js CLI that
grades a website's HTTP security
headers (HSTS, CSP, X-Frame-Options and
more) from A+ to F. Flags dangerous CSP
values ...
Enter
Security VMS
. Features:Intuitive, Responsive and
Resource-effective . This is an
application that can also be fetched
from
https://sourceforge.net/projects/security-vms/....
Enter
security-audit
. security-audit is a coding-agent
skill for running structured security
audits on software repositories. It
organizes the audit into multiple phases
so the ag...
Enter
security-headers
. Zero-dependency Node.js CLI that
grades a website's HTTP security
headers (HSTS, CSP, X-Frame-Options and
more) from A+ to F. Flags dangerous CSP
values ...
Enter
Agentic Security
. The open-source Agentic LLM
Vulnerability Scanner.
Features:Customizable Rule Sets or Agent
based attacksDocumentation
availableExamples availableComprehensi...
Enter
Guia de Cyber Security
. Guia de Cyber Security is a
cybersecurity learning guide for people
entering or specializing in information
security. It collects study resources,
tools, car...
Enter
SCAP Security Guide
. The purpose of this project is to
create security policy content for
various platforms, Red Hat Enterprise
Linux, Fedora, Ubuntu, Debian, SUSE
Linux Enterpri...
Enter
EL.CO_PC security
. EL.CO PC Security & Maintenance
1.3 � un software per Windows progettato
per rendere semplici e immediate la
protezione, la manutenzione e il
controllo d...
Enter
Symfony Security Core
. Part of the Symfony framework, the
Security Core component provides the
foundational tools for managing
authentication, authorization, and
access control in ...
Enter
HTML5 Security Cheatsheet
. H5SC, or the HTML5 Security
Cheatsheet, is a public reference
collection for researching browser-based
cross-site scripting behavior. It
catalogs HTML5-relat...
Enter
security-audit
. security-audit is a coding-agent
skill for running structured security
audits on software repositories. It
organizes the audit into multiple phases
so the ag...
Enter
Symfony Security Bundle
. Symfony Security Bundle is a powerful
tool for adding authentication and
authorization to Symfony applications.
It provides mechanisms for managing user
role...
Enter
Agentic Security
. The open-source Agentic LLM
Vulnerability Scanner.
Features:Customizable Rule Sets or Agent
based attacksDocumentation
availableExamples availableComprehensi...
Enter
DefectDojo
. DefectDojo is a security
orchestration and vulnerability
management platform. DefectDojo allows
you to manage your application security
program, maintain pro...
Enter
KubeArmor
. KubeArmor is a runtime Kubernetes
security engine. It uses eBPF and Linux
Security Modules(LSM) for fortifying
workloads based on Cloud Containers,
IoT/Edge,...
Enter
Code Quality and Security for Java
. Hundreds of unique rules to find Java
bugs, code smells & vulnerabilities.
Sonar static analysis helps you build
and maintain high-quality Java code. Cov...
Enter
Prowler
. Prowler is an Open Source security
tool to perform AWS security best
practices assessments, audits, incident
response, continuous monitoring,
hardening, and ...
Enter
Docker Scout CLI
. Designed to identify security issues,
outdated packages, and potential
compliance problems within container
images, Docker Scout surfaces dependency
vulnerab...
Enter
Kubescape
. An open-source Kubernetes security
platform for your clusters, CI/CD
pipelines, and IDE that seperates out
the security signal from the scanner
noise. Kubesc...
Enter
Code Quality and Security for Java
. Hundreds of unique rules to find Java
bugs, code smells & vulnerabilities.
Sonar static analysis helps you build
and maintain high-quality Java code. Cov...
Enter
How To Secure A Linux Server
. How To Secure A Linux Server is a
practical, evolving guide for hardening
Linux servers in personal, hobby, and
small-scale production environments. It
focus...
Enter
KubeArmor
. KubeArmor is a runtime Kubernetes
security engine. It uses eBPF and Linux
Security Modules(LSM) for fortifying
workloads based on Cloud Containers,
IoT/Edge,...
Enter
Tetragon
. Tetragon is a flexible
Kubernetes-aware security observability
and runtime enforcement tool that
applies policy and filtering directly
with eBPF, allowing fo...
Enter
Cloud Scanner of Death
. Cloud Scanner of Death is a
professional-grade cloud security
assessment tool designed to identify
vulnerabilities, misconfigurations, and
compliance issues ...
Enter
Docker Scout CLI
. Designed to identify security issues,
outdated packages, and potential
compliance problems within container
images, Docker Scout surfaces dependency
vulnerab...
Enter
Shuffle Automation
. Shuffle is an open-source security
automation platform built for security
teams, MSSPs, and service providers. It
helps teams connect tools, automate
repetit...
Enter
secator
. Secator is a task and workflow runner
designed to streamline security
assessments by integrating many
well-known penetration testing and
reconnaissance tools...
Enter
CodeBurn
. CodeBurn is a security-focused tool
designed to evaluate and stress-test
codebases using adversarial techniques,
often leveraging AI to identify
vulnerabilit...
Enter
deepsec
. deepsec is an agent-powered security
harness for finding vulnerabilities in
large codebases. It is designed to run
on the user�s own infrastructure, using
co...
Enter
Stacklok Minder
. Minder by Stacklok is an open source
platform that helps development teams
and open source communities build more
secure software, and prove to others
that w...
Enter
Web-Check
. Comprehensive, on-demand open source
intelligence for any website. Get an
insight into the inner-workings of a
given website: uncover potential attack
vector...
Enter
Arkime
. Arkime is an open source,
large-scale, full packet capturing,
indexing, and database system designed
to augment existing security
infrastructure by storing a...
Enter
secator
. Secator is a task and workflow runner
designed to streamline security
assessments by integrating many
well-known penetration testing and
reconnaissance tools...
Enter
CodeBurn
. CodeBurn is a security-focused tool
designed to evaluate and stress-test
codebases using adversarial techniques,
often leveraging AI to identify
vulnerabilit...
Enter
deepsec
. deepsec is an agent-powered security
harness for finding vulnerabilities in
large codebases. It is designed to run
on the user�s own infrastructure, using
co...
Enter
Obscura
. Obscura is a security-focused project
aimed at providing tools and techniques
for enhancing privacy, anonymity, and
operational security in digital
environme...
Enter
PentestAgent
. PentestAgent is an open-source
autonomous security testing platform
designed to help organizations identify
vulnerabilities and assess security
posture by si...
Enter
Anthropic Cybersecurity Skills
. Anthropic Cybersecurity Skills is a
collection of structured prompts, tools,
and workflows designed to enhance the
cybersecurity capabilities of AI
systems. ...
Enter
Arkime
. Arkime is an open source,
large-scale, full packet capturing,
indexing, and database system designed
to augment existing security
infrastructure by storing a...
Enter
Is Website Vulnerable
. A command-line tool that scans
websites for known security
vulnerabilities in their frontend
dependencies by checking against the
Snyk vulnerability database...
Enter
EMBA
. EMBA is designed as the central
firmware analysis tool for penetration
testers and product security teams. It
supports the complete security analysis
process...
Enter
fleet
. Fleet exposes familiar concepts from
traditional MDMs like custom attributes
and dynamic grouping, but in a way that
lets you work directly with data and eve...
Enter
GuardDog
. guarddog is an open-source security
tool by DataDog designed to detect risks
in open-source dependencies. It helps
developers analyze software supply chain
r...
Enter
OSS-Fuzz
. OSS-Fuzz is a large-scale fuzz
testing platform developed by Google to
improve the security and reliability of
widely used open source software. Fuzz
testing...
Enter
OSCAL
. NIST is developing the Open Security
Controls Assessment Language (OSCAL), a
set of hierarchical, XML-, JSON-, and
YAML-based formats that provide a
standard...
Enter
Xteam
. Xteam is a command-line security
toolkit designed to provide multiple
penetration testing and
information-gathering utilities in a
single interface. It combi...
Enter
Obscura
. Obscura is a security-focused project
aimed at providing tools and techniques
for enhancing privacy, anonymity, and
operational security in digital
environme...
Enter
tirreno
. tirreno is a security framework.
tirreno [tir.?r?.no] helps understand,
monitor, and protect your product from
threats, fraud, and abuse. While classic
cyber...
Enter
OWASP Juice Shop
. It can be used in security trainings,
awareness demos, CTFs and as a guinea
pig for security tools! Juice Shop
encompasses vulnerabilities from the
entire OW...
Enter
var-lib-apt-lists
. This is an application that can also
be fetched from
https://sourceforge.net/projects/var-lib-apt-lists/.
It has been hosted in OnWorks in order
to be run on...
Enter
PentestAgent
. PentestAgent is an open-source
autonomous security testing platform
designed to help organizations identify
vulnerabilities and assess security
posture by si...
Enter
Laravel CSP
. By default, all scripts on a webpage
are allowed to send and fetch data to
any site they want. This can be a
security problem. Imagine one of your
JavaScript...
Enter
wpa-dictionary
. wpa-dictionary is a Wi-Fi security
wordlist repository focused on WPA and
WPA2 password auditing. It collects
several password dictionary files that
can be u...
Enter
Anthropic Cybersecurity Skills
. Anthropic Cybersecurity Skills is a
collection of structured prompts, tools,
and workflows designed to enhance the
cybersecurity capabilities of AI
systems. ...
Enter
BunkerWeb
. Being a full-featured web server
(based on NGINX under the hood), it will
protect your web services to make them
"secure by default". BunkerWeb
integ...
Enter
Is Website Vulnerable
. A command-line tool that scans
websites for known security
vulnerabilities in their frontend
dependencies by checking against the
Snyk vulnerability database...
Enter
Cr3dOv3r
. Cr3dOv3r is a penetration testing and
security auditing tool designed to
demonstrate and analyze the risks
associated with credential reuse across
multiple o...
Enter
fleet
. Fleet exposes familiar concepts from
traditional MDMs like custom attributes
and dynamic grouping, but in a way that
lets you work directly with data and eve...
Enter
EMBA
. EMBA is designed as the central
firmware analysis tool for penetration
testers and product security teams. It
supports the complete security analysis
process...
Enter
Deckhouse
. Deckhouse is a Kubernetes platform
that allows you to create homogeneous
K8s clusters on any infrastructure. It
manages clusters comprehensively and
�automag...
Enter
Vault
. Manage secrets and protect sensitive
data. Secure, store and tightly control
access to tokens, passwords,
certificates, encryption keys for
protecting secret...
Enter
hookprobe
. HookProbe is an open-source AI-native
intrusion detection system (IDS/IPS)
that runs on Raspberry Pi and edge
devices. It combines eBPF/XDP
kernel-level pack...
Enter
GuardDog
. guarddog is an open-source security
tool by DataDog designed to detect risks
in open-source dependencies. It helps
developers analyze software supply chain
r...
Enter
HTTPLeaks
. HTTPLeaks is a security test project
that catalogs ways HTML can cause a
browser or renderer to send external
HTTP requests. Its primary artifact is a
single...
Enter
OWASP Amass
. The OWASP Amass Project has developed
a tool to help information security
professionals perform network mapping of
attack surfaces and perform external
asset...
Enter
CyberStrikeAI
. CyberStrikeAI is an AI-native
security testing platform built in Go
that brings autonomous penetration
testing, vulnerability discovery, and
attack chain ana...
Enter
PentAGI
. PentAGI is a fully autonomous AI
agent system designed to perform complex
penetration testing tasks by
orchestrating multiple intelligent
components into a c...
Enter
thc-hydra
. Number one of the biggest security
holes are passwords, as every password
security study shows. This tool is a
proof of concept code, to give
researchers and...
Enter
Claw Hunter
. Claw Hunter is an open-source
security tool designed to detect,
analyze, and mitigate risks associated
with autonomous AI agents, specifically
those built on...
Enter
Strix
. Strix is an open source agent-driven
security platform that uses autonomous
AI agents to identify, investigate, and
validate vulnerabilities in software
appl...
Enter
AWS EKS Terraform module
. Terraform module which creates AWS
EKS (Kubernetes) resources.
Windows-based node support is limited to
a default user data template that is
provided due to ...
Enter
SecurityHeaderAudit
. SecurityHeaderAudit is a
beginner-friendly defensive security
tool that checks websites for common
HTTP security headers and reports
missing protections. Cat...
Enter
var-lib-apt-lists
. This is an application that can also
be fetched from
https://sourceforge.net/projects/var-lib-apt-lists/.
It has been hosted in OnWorks in order
to be run on...
Enter
Laravel CSP
. By default, all scripts on a webpage
are allowed to send and fetch data to
any site they want. This can be a
security problem. Imagine one of your
JavaScript...
Enter
Spring Boot Demo
. This repository is a hands-on, �deep
learning by doing� collection of Spring
Boot demos that you can run and study
module by module. It currently includes
66...
Enter
Sigma
. Welcome to the Sigma main rule
repository. The place where detection
engineers, threat hunters and all
defensive security practitioners
collaborate on detect...
Enter
wpa-dictionary
. wpa-dictionary is a Wi-Fi security
wordlist repository focused on WPA and
WPA2 password auditing. It collects
several password dictionary files that
can be u...
Enter
Trivy Operator
. The Trivy Operator leverages Trivy to
continuously scan your Kubernetes
cluster for security issues. The scans
are summarised in security reports as
Kubernet...
Enter
BoringSSL
. BoringSSL is a Google-maintained fork
of OpenSSL, designed specifically to
meet the security, performance, and
maintainability needs of Google�s
infrastructu...
Enter
BrowserBox
. Remote isolated browser API for
security, automation visibility and
interactivity. Run-on our cloud, or
bring your own. Full scope double
reverse web proxy w...
Enter
Falco
. Falco is a open source project to
detect abnormal application behavior in
a cloud native environment like
Kubernetes. This cloud native runtime
security proj...
Enter
Pacu
. Pacu (named after a type of Piranha
in the Amazon) is a comprehensive AWS
security-testing toolkit designed for
offensive security practitioners. While
sever...
Enter
Raccoon
. Raccoon is a high-performance
offensive security tool designed to
assist with reconnaissance and
vulnerability scanning during
penetration testing and securi...
Enter
PoisonTap
. PoisonTap is a security research
project that demonstrates risks
involving USB networking, locked
computers, browser sessions, and
internal network exposure....
Enter
nuclei
. Nuclei is used to send requests
across targets based on a template,
leading to zero false positives and
providing fast scanning on a large
number of hosts. N...
Enter
NPQ
. npq is a security-focused package
manager that analyzes npm dependencies
for potential vulnerabilities before
installation. It helps developers ensure
the sa...
Enter
bearer
. Welcome to the Bearer documentation.
Bearer is a static application security
testing (SAST) tool that scans your
source code and analyzes your data flows
to ...
Enter
Trail of Bits Skills Marketplace
. Trail of Bits Skills Marketplace is a
specialized Claude Code skills
marketplace built by the security
research firm Trail of Bits that focuses
on enhancing ...
Enter
Vulnhuntr
. Vulnhuntr is an open source security
tool that uses large language models to
analyze codebases and identify remotely
exploitable vulnerabilities. It focuses ...
Enter
Wazuh
. Wazuh is an open-source, unified
security platform that delivers extended
detection and response (XDR) and SIEM
capabilities for on-premises, cloud,
containe...
Enter
pwd.sh
. pwd.sh is a lightweight command-line
utility designed to generate strong,
secure passwords using simple and
reproducible methods directly from the
terminal. ...
Enter
SimpleSecCamEmailNVR
. Using a security camera with SSL/TLS
e-mail capability, a local-only router,
and a computer/server, receive motion
detection videos and store them in a
local...
Enter
Arcjet
. Arcjet helps developers protect their
apps in just a few lines of code.
Implement rate limiting, bot protection,
email verification, and defense against
comm...
Enter
Claude BugHunter
. Claude-BugHunter is a Claude Code
skill bundle focused on bug hunting,
security testing, and external red-team
research workflows. It packages a large
collec...
Enter
CookieGuardAudit
. CookieGuardAudit is a simple Python
command-line security tool that checks a
website's cookies for common
security flag issues. It helps users
quickly sp...
Enter
CyberStrikeAI
. CyberStrikeAI is an AI-native
security testing platform built in Go
that brings autonomous penetration
testing, vulnerability discovery, and
attack chain ana...
Enter
Lighthouse Ethereum
. Lighthouse is an Ethereum consensus
client that connects to other Ethereum
consensus clients to form a resilient
and decentralized proof-of-stake
blockchain....
Enter
AWS EKS Terraform module
. Terraform module which creates AWS
EKS (Kubernetes) resources.
Windows-based node support is limited to
a default user data template that is
provided due to ...
Enter
thc-hydra
. Number one of the biggest security
holes are passwords, as every password
security study shows. This tool is a
proof of concept code, to give
researchers and...
Enter
nsjail
. A lightweight process isolation tool
that utilizes Linux namespaces, cgroups,
rlimits and seccomp-bpf syscall filters,
leveraging the Kafel BPF language for ...
Enter
StackRox Kubernetes
. The StackRox Kubernetes Security
Platform performs a risk analysis of the
container environment, delivers
visibility and runtime alerts, and
provides recomme...
Enter
Null-CLi
. NullSquare is an AI-powered security
platform that can do both penetration
testing and compliance auditing.
Features:pentestingcompliance auditcode
review A...
Enter
Passbolt API
. Passbolt API is an open-source
password manager designed for teams. It
allows users to securely store and share
passwords using end-to-end encryption.
Passbo...
Enter
Spring Boot Demo
. This repository is a hands-on, �deep
learning by doing� collection of Spring
Boot demos that you can run and study
module by module. It currently includes
66...
Enter
Trivy Operator
. The Trivy Operator leverages Trivy to
continuously scan your Kubernetes
cluster for security issues. The scans
are summarised in security reports as
Kubernet...
Enter
Sigma
. Welcome to the Sigma main rule
repository. The place where detection
engineers, threat hunters and all
defensive security practitioners
collaborate on detect...
Enter
Falco
. Falco is a open source project to
detect abnormal application behavior in
a cloud native environment like
Kubernetes. This cloud native runtime
security proj...
Enter
Mobile Verification Toolkit
. Mobile Verification Toolkit (MVT) is
a collection of utilities to simplify
and automate the process of gathering
forensic traces helpful to identify a
potent...
Enter
Raccoon
. Raccoon is a high-performance
offensive security tool designed to
assist with reconnaissance and
vulnerability scanning during
penetration testing and securi...
Enter
NPQ
. npq is a security-focused package
manager that analyzes npm dependencies
for potential vulnerabilities before
installation. It helps developers ensure
the sa...
Enter
Trail of Bits Skills Marketplace
. Trail of Bits Skills Marketplace is a
specialized Claude Code skills
marketplace built by the security
research firm Trail of Bits that focuses
on enhancing ...
Enter
Vulnhuntr
. Vulnhuntr is an open source security
tool that uses large language models to
analyze codebases and identify remotely
exploitable vulnerabilities. It focuses ...
Enter
DEVIL FISH
. Devil-Fish is a Windows application
for analyzing Portable Executable (PE)
files such as EXE and DLL files. It
provides information about the file
structure,...
Enter
LibreSign
. Simplify your digital signatures and
document management safely and
efficiently. Beyond offering agility and
security in digital signatures and
document mana...
Enter
Zen Browser
. Experience tranquillity while
browsing the web without people tracking
you. Beautifully designed,
privacy-focused, and packed with
features. We care about yo...
Enter
Arcjet
. Arcjet helps developers protect their
apps in just a few lines of code.
Implement rate limiting, bot protection,
email verification, and defense against
comm...
Enter
Exploitarium
. Exploitarium is a consolidated
archive of public proof-of-concept
vulnerability research and exploit
writeups. It gathers older standalone
research repositor...
Enter
SonarQube
. SonarQube empowers all developers to
write cleaner and safer code. Thousands
of automated Static Code Analysis rules,
protecting your app on multiple fronts,...
Enter
Django Hijack
. With Django Hijack, admins can log in
and work on behalf of other users
without having to know their
credentials. 3.x docs are available in
the docs folder. ...
Enter
Anya
. Anya is a privacy-first static
malware analysis tool for Windows,
Linux, and macOS. It combines PE, ELF,
and Mach-O binary analysis with MITRE
ATT&CK map...
Enter
truffleHog
. truffleHog searches through git
repositories for high entropy strings
and secrets, digging deep into commit
history. TruffleHog runs behind the
scenes to sca...
Enter
Arduino IDE
. This repository contains the source
code of the Arduino IDE 2.x, which is
currently in the beta stage. The Arduino
IDE 2.x is a major rewrite, sharing no
cod...
Enter
Trivy
. Trivy is the most popular open source
security scanner, reliable, fast, and
easy to use. Use Trivy to find
vulnerabilities & IaC
misconfigurations, SBOM ...
Enter
Venom
. Venom is a Go-based multi-hop proxy
tool designed for authorized penetration
testing, red-team labs, and security
education. It helps operators connect
multi...
Enter
XSS Challenge Wiki
. XSS Challenge Wiki is an archived
community knowledge base documenting
solutions and results from cross-site
scripting challenges. It was created to
preserve...
Enter
nebula
. Nebula is a scalable overlay
networking tool with a focus on
performance, simplicity and security. It
lets you seamlessly connect computers
anywhere in the w...
Enter
Master Spring and Spring Boot
. Master Spring and Spring Boot is a
comprehensive educational project that
teaches how to build enterprise-grade
Java applications using the Spring
ecosystem....
Enter
Passbolt API
. Passbolt API is an open-source
password manager designed for teams. It
allows users to securely store and share
passwords using end-to-end encryption.
Passbo...
Enter
T3MP3ST
. T3MP3ST is a multi-agent offensive
security framework for authorized
red-team research, CTFs, and security
education. It wraps an existing AI
coding agent wi...
Enter
Stegcore
. Stegcore combines cryptography and
steganography to hide encrypted data
inside ordinary files. It encrypts your
payload before embedding it, so the
hidden co...
Enter
Mobile Verification Toolkit
. Mobile Verification Toolkit (MVT) is
a collection of utilities to simplify
and automate the process of gathering
forensic traces helpful to identify a
potent...
Enter
Defending Code Reference Harness
. Defending Code Reference Harness is a
reference implementation for autonomous
vulnerability discovery and remediation
with Claude. It is designed for securit...
Enter
Rancher
. From datacenter to cloud to edge,
Rancher lets you deliver
Kubernetes-as-a-Service. Rancher is a
complete software stack for teams
adopting containers. It ad...
Enter
Copy Fail - CVE-2026-31431
. Copy Fail - CVE-2026-31431 is a
proof-of-concept repository that
demonstrates and analyzes a specific
Linux kernel vulnerability identified as
CVE-2026-31431...
Enter
Universal Intel Wi-Fi BT Drivers Updater
. Universal Intel Wi-Fi & Bluetooth
Drivers Updater automatically detects
Intel wireless hardware and installs the
latest official drivers with enterprise-...
Enter
SkillSpector
. SkillSpector is a security scanner
built to evaluate AI agent skills before
they are installed or trusted. It helps
teams inspect skills used by tools such
a...
Enter
InterceptSuite
. InterceptSuite is a cross?platform,
SOCKS5?based MITM proxy specially
designed to intercept, inspect, analyze,
and manipulate encrypted network traffic
at th...
Enter
CrowdSec
. CrowdSec - an open-source massively
multiplayer firewall able to analyze
visitor behavior & provide an
adapted response to all kinds of
attacks. It also ...
Enter
frida
. Dynamic instrumentation toolkit for
developers, reverse-engineers, and
security researchers. Inject your own
scripts into black box processes. Hook
any funct...
Enter
Bionic GPT
. Bionic is an on-premise generative AI
platform positioned as a private
replacement for ChatGPT, with a strong
emphasis on data confidentiality, team
collabor...
Enter
Ajv JSON schema validator
. Security and reliability for
JavaScript applications. Ensure your
data is valid as soon as it's
received. Instead of having your data
validation and sani...
Enter
SpringBoot Labs
. SpringBoot-Labs is a comprehensive
learning and reference repository
created by yudaocode that explores
advanced concepts, features, and best
practices in Sp...
Enter
NextDNS
. NextDNS protects you from all kinds
of security threats, blocks ads and
trackers on websites and in apps and
provides a safe and supervised Internet
for kids...
Enter
SpringAll
. SpringAll is a comprehensive learning
project that gathers a wide range of
Spring, Spring Boot, and Spring Cloud
demos in one repository. It is designed
for ...
Enter
Inventory
. Trickest Inventory is an open source
dataset and workflow collection designed
to provide an extensive asset inventory
for public bug bounty programs. The rep...
Enter
Skill Scanner
. This repository is a public
security-focused scanning tool intended
to analyze and assess AI agent skills
for potential issues, quality concerns,
and vulnera...
Enter
Sn1per
. Sn1per is an offensive-security
platform that combines reconnaissance,
vulnerability scanning, exploitation,
and reporting in organized workspaces.
It automa...
Enter
LINKERD
. Enterprise power without enterprise
complexity. Linkerd adds security,
observability, and reliability to any
Kubernetes cluster. 100% open source,
CNCF gradu...
Enter
Harpoon
. Harpoon is a command line tool
designed to assist with open source
intelligence (OSINT) and threat
intelligence investigations. It helps
security professiona...
Enter
Scalytics Open Intelligence - OSINT
. EUOSINT is the open-source edition of
the OSINT pipeline built by Scalytics
for real-world intelligence monitoring,
situation analysis, and risk detection.
I...
Enter
OpenFang
. OpenFang is an open-source agent
operating system designed to orchestrate
autonomous AI agents and workflows in a
structured, production-oriented
environment...
Enter
MagSpoof
. MagSpoof is a hardware and security
research project that demonstrates
magnetic stripe emulation. It was
created to explore how magnetic stripe
systems work ...
Enter
Monkey Code
. Monkey Code is an enterprise-grade AI
programming assistant designed to
transform how development teams
collaborate, build, and manage code
across complex en...
Enter
Pterodactyl Panel
. Pterodactyl� is a free, open-source
game server management panel built with
PHP, React, and Go. Designed with
security in mind, Pterodactyl runs all
game ser...
Enter
Anya
. Anya is a privacy-first static
malware analysis tool for Windows,
Linux, and macOS. It combines PE, ELF,
and Mach-O binary analysis with MITRE
ATT&CK map...
Enter
Exploitarium
. Exploitarium is a consolidated
archive of public proof-of-concept
vulnerability research and exploit
writeups. It gathers older standalone
research repositor...
Enter
CloudQuery
. CloudQuery extracts, transforms and
loads your cloud assets into normalized
PostgreSQL tables. CloudQuery enables
you to assess, audit, and monitor the
confi...
Enter
Conscrypt
. Conscrypt is a modern TLS/SSL
provider for Java that replaces the
default JCE/JCA crypto stack with one
backed by BoringSSL for better
performance and securi...
Enter
malware_training_vol1
. malware_training_vol1 is an
educational repository for Windows
malware analysis training. It is
designed to help learners understand
common malware technique...
Enter
SonarQube
. SonarQube empowers all developers to
write cleaner and safer code. Thousands
of automated Static Code Analysis rules,
protecting your app on multiple fronts,...
Enter
FinalRecon
. FinalRecon is an all-in-one web
reconnaissance tool written in Python
that helps security professionals gather
information about a target website
quickly and...
Enter
GitLab
. GitLab is a single-application DevOps
platform that brings source control,
CI/CD, package registries, security
scanning, and deployment pipelines under
one r...
Enter
truffleHog
. truffleHog searches through git
repositories for high entropy strings
and secrets, digging deep into commit
history. TruffleHog runs behind the
scenes to sca...
Enter
gitGraber
. gitGraber is a Python-based security
tool designed to monitor GitHub in real
time to detect exposed sensitive
information in publicly indexed
repositories. I...
Enter
Master Spring and Spring Boot
. Master Spring and Spring Boot is a
comprehensive educational project that
teaches how to build enterprise-grade
Java applications using the Spring
ecosystem....
Enter
DeathStar
. DeathStar is a Python-based red-team
automation project that integrates with
the Empire REST API for Active Directory
security assessment. Its main purpose i...
Enter
multiOTP open source
. multiOTP is a PHP class, a powerful
command line utility and a web interface
developed by SysCo syst�mes de
communication sa in order to provide a
completely...
Enter
Lantern
. Can't access your favorite apps?
Download Lantern to easily access
videos, messaging, and other popular
apps while at school or work. Lantern is
an appli...
Enter
Rancher
. From datacenter to cloud to edge,
Rancher lets you deliver
Kubernetes-as-a-Service. Rancher is a
complete software stack for teams
adopting containers. It ad...
Enter
Defending Code Reference Harness
. Defending Code Reference Harness is a
reference implementation for autonomous
vulnerability discovery and remediation
with Claude. It is designed for securit...
Enter
Stegcore
. Stegcore combines cryptography and
steganography to hide encrypted data
inside ordinary files. It encrypts your
payload before embedding it, so the
hidden co...
Enter
Wapiti
. Wapiti is a vulnerability scanner for
web applications. It currently search
vulnerabilities like XSS, SQL and XPath
injections, file inclusions, command
exec...
Enter
The Book of Secret Knowledge
. The Book of Secret Knowledge is a
large curated knowledge base for
developers, system administrators,
security learners, and technical power
users. It collec...
Enter
SkillSpector
. SkillSpector is a security scanner
built to evaluate AI agent skills before
they are installed or trusted. It helps
teams inspect skills used by tools such
a...
Enter
Full Stack Computer Scanner
. The Full Stack Computer Scanner is a
read-only Windows security diagnostics
tool for system awareness. No ads. No
accounts. No data collection. Fully
offline...
Enter
SpringBoot Labs
. SpringBoot-Labs is a comprehensive
learning and reference repository
created by yudaocode that explores
advanced concepts, features, and best
practices in Sp...
Enter
NextDNS
. NextDNS protects you from all kinds
of security threats, blocks ads and
trackers on websites and in apps and
provides a safe and supervised Internet
for kids...
Enter
SpringAll
. SpringAll is a comprehensive learning
project that gathers a wide range of
Spring, Spring Boot, and Spring Cloud
demos in one repository. It is designed
for ...
Enter
Skill Scanner
. This repository is a public
security-focused scanning tool intended
to analyze and assess AI agent skills
for potential issues, quality concerns,
and vulnera...
Enter
LINKERD
. Enterprise power without enterprise
complexity. Linkerd adds security,
observability, and reliability to any
Kubernetes cluster. 100% open source,
CNCF gradu...
Enter
Pterodactyl Panel
. Pterodactyl� is a free, open-source
game server management panel built with
PHP, React, and Go. Designed with
security in mind, Pterodactyl runs all
game ser...
Enter
Harpoon
. Harpoon is a command line tool
designed to assist with open source
intelligence (OSINT) and threat
intelligence investigations. It helps
security professiona...
Enter
Monkey Code
. Monkey Code is an enterprise-grade AI
programming assistant designed to
transform how development teams
collaborate, build, and manage code
across complex en...
Enter
CloudQuery
. CloudQuery extracts, transforms and
loads your cloud assets into normalized
PostgreSQL tables. CloudQuery enables
you to assess, audit, and monitor the
confi...
Enter
Conscrypt
. Conscrypt is a modern TLS/SSL
provider for Java that replaces the
default JCE/JCA crypto stack with one
backed by BoringSSL for better
performance and securi...
Enter
ByteHook
. ByteHook is a ByteDance-hosted
project whose name suggests a hooking or
instrumentation library, likely used for
hooking system calls or API calls for
monito...
Enter
Tiki Wiki CMS Groupware
. "Software made the wiki way"
A full-featured, web-based, tightly
integrated, all-in-one
Wiki+CMS+Groupware, Free Source Software
(GNU/LGPL), using PH...
Enter
uncover
. Uncover is an open source
reconnaissance tool designed to quickly
discover exposed hosts on the internet
by querying multiple search engine APIs
through a un...
Enter
gitGraber
. gitGraber is a Python-based security
tool designed to monitor GitHub in real
time to detect exposed sensitive
information in publicly indexed
repositories. I...
Enter
Tutanota
. Tutanota is an open source email
client focused on security and privacy.
It is built with end-to-end encryption
and 2FA, so you can be assured of utmost
emai...
Enter
tracecat
. Tracecat is an open-source Tines /
Splunk SOAR alternative for security
engineers. We're building the
features of Tines using enterprise-grade
open-sourc...
Enter
Coin Wallet
. Coin Wallet is a non-custodial
multicurrency wallet for multiple
platforms. A secure, user-friendly
cryptocurrency wallet focused on
providing essential feat...
Enter
ProxyCrypt
. ProxyCrypt is a command line tool
that creates encrypted volumes within a
file or a hard drive. Encryption and
decryption are made on the fly, allowing
you t...
Enter
WhatWeb
. WhatWeb is a Ruby-based web scanner
for fingerprinting websites. It
identifies CMS, server technologies,
JavaScript frameworks, and other
characteristics by ...
Enter
Advanced-Root-Checker
. Advanced Root Checker is a free,
open-source Android app that detects if
your device has been rooted. All 33
checks run entirely offline on your
device. No i...
Enter
AWS Nitro Enclaves SDK for C
. This repo provides a C API for AWS
Nitro Enclaves, including a KMS SDK that
integrates it with attestation. The
simplest way to use this SDK is by using
one ...
Enter
PrivateBin
. PrivateBin is a minimalist,
open-source online pastebin that allows
users to securely share text data. It
encrypts the content client-side,
ensuring that no ...
Enter
SipLine
. SipLine is a modern, lightweight SIP
softphone for Windows 10/11 built with
.NET 9 WPF. It provides enterprise-grade
VoIP communication with a focus on perfo...
Enter
WPScan
. WPScan is a black-box WordPress
vulnerability scanner written in Ruby.
It analyzes WordPress sites to identify
outdated core, plugins, themes, exposed
APIs, ...
Enter
LLF-Tool-for-Linux
. This is an open-source alternative
for applying LLF processes to mechanical
hard drives on Debian-based systems,
modeled after HDD GURU's famous
software...
Enter