Security

安全工具与实践

ossec/ossec-hids

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

C 5.0k 1.1k GPL-2.0
compliance file-integrity-management fim hids +7

google/google-ctf

Google CTF

Python 5.0k 595 Apache-2.0
ctf ctf-challenges google security

ClearURLs/Addon

ClearURLs is an add-on based on the new WebExtensions technology and will automatically remove tracking elements from URLs to help protect your privacy.

JavaScript 5.0k 142 LGPL-3.0
addon addons-mozilla-org anti-tracking chrome +5

cheatsnake/backend-cheats

📃 White paper for Backend developers

5.0k 507 MIT
architectural-patterns architecture awesome awesome-list +15

Hack-with-Github/Free-Security-eBooks

Free Security and Hacking eBooks

5.0k 1.1k
cloud-security cyber-security ebooks forensics +6

hahwul/WebHackersWeapons

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Ruby 4.9k 825 MIT
awesome-list bugbounty bugbountytips hacking +5

microsoft/agent-governance-toolkit

AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.

Python 4.9k 788 MIT
agent-framework ai-agents ai-safety compliance +8

andresriancho/w3af

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Python 4.9k 1.2k
appsec cross-site-scripting scanner security +1

cilium/tetragon

eBPF-based Security Observability and Runtime Enforcement

C 4.9k 574 Apache-2.0
bpf ebpf kernel kubernetes +1

DefectDojo/django-DefectDojo

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

HTML 4.8k 1.9k BSD-3-Clause
analytics appsec automation devsecops +11

nicocha30/ligolo-ng

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

Go 4.8k 454 GPL-3.0
golang offensive-security pentest-tool pentesting +5

Security-Onion-Solutions/securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

Shell 4.8k 666 NOASSERTION
case-management cyber-security endpoint-security information-security +6

urbanadventurer/Android-PIN-Bruteforce

Unlock an Android phone (or device) by bruteforcing the lockscreen PIN. Turn your Kali Nethunter phone into a bruteforce PIN cracker for Android devices! (no root, no adb)

Shell 4.7k 833
android android-security bruteforce kali-linux +4

aya-rs/aya

Aya is an eBPF library for the Rust programming language, built with a focus on developer experience and operability.

Rust 4.7k 455 Apache-2.0
bpf ebpf observability rust +1

0x4D31/awesome-threat-detection

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

4.7k 760
awesome awesome-list detection incident-response +3

forter/security-101-for-saas-startups

security tips for startups

4.7k 290 NOASSERTION
chinese security security-considerations startup

AliyunContainerService/pouch

An Efficient Enterprise-class Container Engine

Go 4.6k 938 Apache-2.0
cloud-native containers efficiency go +5

build-trust/ockam

Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications – at massive scale.

Rust 4.6k 557 Apache-2.0
authentication authorization credentials distributed-systems +14

slowmist/Knowledge-Base

Knowledge Base 慢雾安全团队知识库

4.6k 597
blockchain hacking knowledge-base security

ReversecLabs/drozer

The Leading Security Assessment Framework for Android.

Python 4.6k 842 NOASSERTION
android drozer java mobile +4

openziti/zrok

Secure internet sharing made simple.

Go 4.6k 215 Apache-2.0
file-sharing golang network peer-to-peer +3

aquasecurity/tracee

Linux Runtime Security and Forensics using eBPF

Go 4.6k 505 Apache-2.0
bpf docker ebpf golang +4

YauhenKavalchuk/interview-questions

Популярные HTML / CSS / JavaScript / ECMAScript / TypeScript / React / Vue / Angular / Node вопросы на интервью и ответы на них (https://tinyurl.com/wxysrpsy)

4.5k 594
accessibility angular css ecmascript +12

google/santa

A binary authorization and monitoring system for macOS

Objective-C++ 4.5k 287 Apache-2.0
allowlist authorization blocklist endpoint-security +4

cerbos/cerbos

Cerbos is the open core, language-agnostic, scalable authorization solution that makes user permissions and authorization simple to implement and manage by writing context-aware access control policies for your application resources.

Go 4.5k 198 Apache-2.0
access-control authorization go golang +3

M66B/FairEmail

Fully featured, open source, privacy friendly email app for Android

Java 4.5k 691 GPL-3.0
android app email privacy +1

HotCakeX/Harden-Windows-Security

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Personal, Enterprise, Government and Military security levels | SLSA Level 3 Compliant for Secure Development and Build Process | Apps Available on MS Store✨

C# 4.5k 324 MIT
1st-party-security applicationcontrol audit bitlocker +16

firmianay/CTF-All-In-One

CTF竞赛权威指南

C 4.5k 713 CC-BY-SA-4.0
book crypto ctf exploit +6

sensepost/gowitness

🔍 gowitness - a golang, web screenshot utility using Chrome Headless

Go 4.5k 441 GPL-3.0
chrome chrome-headless fingerprint footprinting +7

projectdiscovery/interactsh

An OOB interaction gathering server and client library

Go 4.5k 472 MIT
appsec bugbounty dns golang +7