security-tools

There are 5604 repositories under security-tools topic.

  • x64dbg

    x64dbg/x64dbg

    An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

    Language:C++46.9k2.7k2.6k2.6k
  • aquasecurity/trivy

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

    Language:Go28.9k1842.9k2.7k
  • web-check

    Lissy93/web-check

    🕵️‍♂️ All-in-one OSINT tool for analysing any website

    Language:TypeScript26.5k1501202.1k
  • gitleaks/gitleaks

    Find secrets with Gitleaks 🔑

    Language:Go23.2k1729061.8k
  • trufflehog

    trufflesecurity/trufflehog

    Find, verify, and analyze leaked credentials

    Language:Go21.7k1988462k
  • infisical

    Infisical/infisical

    Infisical is the open-source platform for secrets management, PKI, and SSH access.

    Language:TypeScript20.1k479011.4k
  • dotenv

    motdotla/dotenv

    Loads environment variables from .env for nodejs projects.

    Language:JavaScript20k104513899
  • personal-security-checklist

    Lissy93/personal-security-checklist

    🔒 A compiled checklist of 300+ tips for protecting digital security and privacy in 2024

    Language:TypeScript19.6k228941.4k
  • RustScan

    bee-san/RustScan

    🤖 The Modern Port Scanner 🤖

    Language:Rust18k1372691.2k
  • fail2ban/fail2ban

    Daemon to ban hosts that cause multiple authentication errors

    Language:Python15.4k2572.4k1.4k
  • smicallef/spiderfoot

    SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

    Language:Python15.3k3796312.6k
  • CISOfy/lynis

    Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

    Language:Shell14.6k3438761.5k
  • wazuh/wazuh

    Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

    Language:C13.5k22619.8k2k
  • social-analyzer

    qeeqbox/social-analyzer

    API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

    Language:JavaScript12.9k369791.1k
  • prowler

    prowler-cloud/prowler

    Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments & audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, ENS and more

    Language:Python12.1k1241.2k1.8k
  • future-architect/vuls

    Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

    Language:Go11.7k3286301.2k
  • secdev/scapy

    Scapy: the Python-based interactive packet manipulation program & library.

    Language:Python11.7k2321.7k2.1k
  • BishopFox/sliver

    Adversary Emulation Framework

    Language:Go10k1568321.4k
  • edoardottt/awesome-hacker-search-engines

    A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

    Language:Shell9.4k140121894
  • toniblyx/my-arsenal-of-aws-security-tools

    List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

    Language:Shell9.3k392331.6k
  • Sn1per

    1N3/Sn1per

    Attack Surface Management Platform

    Language:Shell9.1k3343412k
  • MyIP

    jason5ng32/MyIP

    The best IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability, whois search and more! || 🇨🇳 可能是最好用的IP工具箱。轻松检查你的 IP,IP 地理位置,检查DNS泄漏,检查 WebRTC 连接,速度测试,ping 测试,MTR测试,检查网站可用性,查询 Whois 信息等等。

    Language:Vue9k31891k
  • securego/gosec

    Go security checker

    Language:Go8.4k84500657
  • rengine

    yogeshojha/rengine

    reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

    Language:HTML8.1k1439111.3k
  • google/osv-scanner

    Vulnerability scanner written in Go which uses the data provided by https://osv.dev

    Language:Go7.7k66387454
  • certificates

    smallstep/certificates

    🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.

    Language:Go7.6k79651493
  • bandit

    PyCQA/bandit

    Bandit is a tool designed to find common security issues in Python code.

    Language:Python7.3k70669686
  • RedTeam-Tools

    A-poc/RedTeam-Tools

    Tools and Techniques for Red Team / Penetration Testing

  • trickest/cve

    Gather and update all available and newest CVEs with their PoC.

    Language:HTML7.2k35950912
  • brakeman

    presidentbeef/brakeman

    A static analysis security vulnerability scanner for Ruby on Rails applications

    Language:Ruby7.1k165795755
  • traitor

    liamg/traitor

    :arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

    Language:Go7k12042643
  • monkey

    guardicore/monkey

    Infection Monkey - An open-source adversary emulation platform

    Language:Python6.9k2351.5k807
  • reconftw

    six2dez/reconftw

    reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

    Language:Shell6.7k1154841.1k
  • awesome-shodan-queries

    jakejarvis/awesome-shodan-queries

    🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩‍💻

  • The-Z-Labs/linux-exploit-suggester

    Linux privilege escalation auditing tool

    Language:Shell6.2k128321.1k
  • urbanadventurer/WhatWeb

    Next generation web scanner

    Language:Ruby6.1k177216963