y-mehta's Stars
amalmurali47/onaws
Fetch the details of assets hosted on AWS.
DarthBenro008/dotCloud
A simple and safe replacement to .env files
securego/gosec
Go security checker
slackhq/goSDL
goSDL
sverweij/dependency-cruiser
Validate and visualize dependencies. Your rules. JavaScript, TypeScript, CoffeeScript. ES6, CommonJS, AMD.
electron/governance
Public repository for governance issues and documents
xdavidhu/awesome-google-vrp-writeups
🐛 A list of writeups from the Google VRP Bug Bounty program
security-prince/Resources-for-Application-Security
Some good resources for getting started with application security
stripe/smokescreen
A simple HTTP proxy that fogs over naughty URLs
jeevan-singh/Security-Engineering-Training
segmentio/threat-modeling-training
Segment's Threat Modeling training for our engineers
initstring/dirty_sock
Linux privilege escalation exploit via snapd (CVE-2019-7304)
reider-roque/linpostexp
Linux post exploitation enumeration and exploit checking tools
doyensec/regexploit
Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)
doyensec/awesome-electronjs-hacking
A curated list of awesome resources about Electron.js (in)security
firecracker-microvm/firecracker
Secure and fast microVMs for serverless computing.
localstack/localstack
💻 A fully functional local AWS cloud stack. Develop and test your cloud & Serverless apps offline
ossf/scorecard
OpenSSF Scorecard - Security health metrics for Open Source
socketio/socket.io
Realtime application framework (Node.JS server)
nikitastupin/clairvoyance
Obtain GraphQL API schema even if the introspection is disabled
Santandersecurityresearch/corsair_scan
Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).
danielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
nccgroup/singularity
A DNS rebinding attack framework.
postmanlabs/newman
Newman is a command-line collection runner for Postman
doyensec/electronegativity
Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.
sathishvj/awesome-gcp-certifications
Google Cloud Platform Certification resources.
security-prince/Application-Security-Engineer-Interview-Questions
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
boyney123/github-actions
Open source list of GitHub Actions. Free free to submit a PR to add your action
google/cadvisor
Analyzes resource usage and performance characteristics of running containers.
Opmantek/open-audit
Tracking and reporting for IT and related assets and configuration