Stars
⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
Cortex: a Powerful Observable Analysis and Active Response Engine
TheHive is a Collaborative Case Management Platform, now distributed as a commercial version
A list of free, public, forward proxy servers. UPDATED DAILY!
IP Intelligence is a free Proxy VPN TOR and Bad IP detection tool to prevent Fraud, stolen content, and malicious users. Block proxies, VPN connections, web host IPs, TOR IPs, and compromised syste…
ipsets dynamically updated with firehol's update-ipsets.sh script
Create actionable data from your Vulnerability Scans
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
Tink is a multi-language, cross-platform, open source library that provides cryptographic APIs that are secure, easy to use correctly, and hard(er) to misuse.
A high performance offensive security tool for reconnaissance and vulnerability scanning
A toolkit for building secure, portable and lean operating systems for containers
eBPF-based Networking, Security, and Observability
Tamper Dev is an extension that allows you to intercept and edit HTTP/HTTPS requests and responses as they happen without the need of a proxy. Works across all operating systems (including Chrome OS).
Proof-of-concept codes created as part of security research done by Google Security Team.
[DEPRECATED] Stanford Javascript Crypto Library
OpenPGP implementation for JavaScript
A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
Device information and digital fingerprinting written in pure JavaScript.
A book series (2 published editions) on the JS language.
Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.
Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.
Red team Arsenal - An intelligent scanner to detect security vulnerabilities in company's layer 7 assets.
Automated Security Testing For REST API's
Easy automated vulnerability scanning, reporting and analysis
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).
SQL powered operating system instrumentation, monitoring, and analytics.