-
cargo-auditable
Make production Rust binaries auditable
-
zizmor
Static analysis for GitHub Actions
-
rustsec
Client library for the RustSec security advisory database
-
urx
Extracts URLs from OSINT Archives for Security Insights
-
shavee
program to automatically decrypt and mount ZFS datasets using Yubikey HMAC as 2FA or any USB drive with support for PAM to auto mount home directories
-
unicop
scanning source code for potentially malicious unicode code points. Helps prevent Trojan source bidi attacks, homoglyph attacks, invisible character attacks etc. Intended to run manually…
-
cosmian_kmip
Cosmian KMIP library
-
walker-common
Common functionality for SBOM and CSAF walker
-
mollify-core
Analysis engines for Mollify: dead code, dependency hygiene, architecture, complexity, duplication, security, type health, coverage, and supply chain
-
clamav-client
ClamAV client library with optional support for async-std, smol, and Tokio
-
polycvss
CVSS v2, v3, and v4 vector string parser and score calculator
-
rustdllproxy
ease the development of proxy DLLs in Rust
-
hakoniwa
Process isolation for Linux using namespaces, resource limits, cgroups, landlock and seccomp
-
runsc-sentry-guard
An ultra-lightweight active incident response daemon for runsc (gVisor) sandboxes
-
ureld
& fast URLs de-cluttering tool written in Rust
-
ntoseye
Windows kernel debugger for Linux hosts running Windows under KVM/QEMU
-
lazynmap
A TUI for interactively generating nmap commands
-
pyscan
python dependency vulnerability scanner
-
dnsm
Toolkit for covert data exfiltration using DNS
-
audit-check
Github Action to run 'cargo audit' on your Rust project
-
idalib
Idiomatic bindings to IDA SDK
-
dz6
A vim-inspired, TUI-based hexadecimal editor
-
cargo-crev
Distributed Code REView system for verifying security and quality of Cargo dependencies
-
gigacode
Sandbox Agent CLI with OpenCode attach by default
-
cargo-ddd
A cargo subcommand for inspecting what changes brings dependency version update into your project
-
symbi-dsl
Symbi DSL - AI-native programming language with Tree-sitter integration
-
libverify-core
Platform-agnostic SDLC verification engine — evidence model, controls, assessment
-
sandlock-ffi
C ABI for sandlock process sandbox
-
aws-sdk-codegurusecurity
AWS SDK for Amazon CodeGuru Security
-
hyperlight-js
that enables JavaScript code to be run inside lightweight Virtual Machine backed Sandbox. It is built on top of Hyperlight
-
miss-demeanor
Fast, parallel, pluggable process compliance checker
-
sbe-core
Core library for sbe — cross-platform sandbox executor for supply chain defense
-
cosmian_kms_interfaces
exposing APIs for plugins to the Cosmian KMS
-
nyx-scanner
A multi-language static analysis tool for detecting security vulnerabilities
-
cvss
Common Vulnerability Scoring System parser/serializer
-
rhabdomancer
Vulnerability research assistant that locates calls to potentially insecure API functions in a binary file
-
winevt-analysis
MITRE-tagged forensic detectors for Windows Event Log artifacts
-
rattler_sandbox
run executables in a sandbox
-
libturnstile
Seccomp-unotify access tracer and namespace-based sandboxing library
-
process_hollowing
Creates a process and overwrites the entry point with shellcode (default to a reverse shell on localhost:4444)
-
mewt
Mutation testing framework with multi-language support
-
cargo-sbom
Create software bill of materials (SBOM) for Rust
-
secure-types
Secure data types that protect sensitive data in memory via locking and zeroization
-
lsec
Laravel Security Audit CLI - scans Laravel applications for security issues, insecure patterns, and risky configuration
-
dinvk
Dynamically invoke arbitrary code in Rust (Dinvoke)
-
sbom-tools
Semantic SBOM diff and analysis tool
-
libscemu
x86 32/64bits and system internals emulator, for securely emulating malware and other stuff
-
capa
File capability extractor
-
gommage-cli
Gommage command-line interface
-
microsandbox-metrics
Shared-memory live metrics registry for microsandbox
-
injectum
The modern, type-safe process injection framework for Red Teams and Offensive Security in Rust
-
packguard-policy
PackGuard policy engine: offset rules, pins, recommended-version computation
-
i2pd-launch
Launches i2pd with clean state
-
atm-storage
Shared audited storage contract and canonical domain types for ATM
-
mcp-security-advisory
Security Advisory MCP Server — search advisories (CVE/GHSA/OSV/RustSec), map to dependencies, score risk, generate patch plans, export evidence
-
osv
parsing the OSV schema and client API
-
repl-core
Core REPL engine for the Symbi platform
-
periodic-audit
run cargo-audit periodically and send email reports
-
doctor-ferris
High-performance, modular dynamic library injection across Windows, Linux, and macOS
-
ThreatDeck
Terminal-based threat intelligence monitoring and alerting platform
-
rullama-permission
Permission policies, audit logging, and trust profiles for rullama
-
endpoint-sec
High-level Rust wrappers around the Endpoint Security Framework
-
get-cve
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
openvet
Command-line tool for checking project conformance against auditing requirements, and authoring, signing and publishing software dependency audits
-
vaas
Check files and hashes for malicious content
-
rite
Author, execute, and verify cryptographic key ceremonies (the
riteCLI) -
birdcage
Cross-platform embeddable sandbox
-
gitlab-cargo-audit
Generate GitLab Dependency Scanning report using
cargo-audit -
kastellan-core
Agent core: scheduler, memory orchestration, policy gate, LLM router, IPC, audit log
-
apohara-agentguard
Deterministic, offline, no-model safety hook + local seccomp+Landlock sandbox + input firewall for Claude Code
-
sandogasa-pkg-health
Audit package health across a sandogasa inventory
-
swh-osv
Mine data from vulnerability databases in the OSV format
-
si-security-audit-room
PLATO Security Audit Room — automated security auditing as a Rust engine block
-
defect-sandbox
Sandboxing and command execution policy primitives for the defect agent
-
spotspoof-cli
Domain spoofing & IDN/Punycode detection for security automation workflows
-
il2cpp_dumper
A blazing fast and reliable il2cpp dumper cross platfrom
-
synapse-waf
High-performance WAF and reverse proxy with embedded intelligence — built on Cloudflare Pingora
-
attestation-validator
Validates attestation certificate chains and inspects attestation certificates
-
actix-web-ratelimit
highly customizable rate limiter for actix-web 4
-
modgunn
Móðguðr — the nordisk security + SCIP world-delta gatekeeper. Guards the bridge (Gjallarbrú): scrutinizes what passes (CVE/license/provenance verdict) and tracks every change in the dependency world…
-
palisade-correlation
Security-conscious correlation engine for Palisade honeypot and deception deployments
-
dmg-cracker
performing dictionary attacks on encrypted DMG images on OSX
-
hipcheck
Automatically assess and score software packages for supply chain risk
-
cargo-audit
Audit Cargo.lock for crates with security vulnerabilities
-
openvet-policy
Requirement language and Kleene evaluator for OpenVet audit policies
-
vervet-scope
Authorization spine: signed scope manifests and the unforgeable Grant capability token
-
lockrail
Local-first secret firewall for AI coding tools
-
ciranda
A deterministic password generator
-
craton-hsm-admin
Admin CLI for Craton HSM — token init, key management, PIN operations
-
cf-gears-credstore
credstore gear module
-
fleetreach-report
Side-effect-free rendering of a FleetReport to table and JSON
-
tauri-dumper
dump assets from a Tauri app
-
libverify-github
GitHub connector for libverify SDLC verification
-
rkh-chk
Command line companion tool to Rootkit Hunter
-
ai-sandbox
Cross-platform AI tool sandbox security implementation
-
process_migration
Overwrites a running process' next instruction(s) with shellcode (default to a reverse shell on localhost:4444)
-
auditable-extract
Extract the dependency trees embedded in binaries by
cargo auditable -
yara-x-cli
A command-line interface for YARA-X
-
dearxan
Static analyzer and patcher for the Arxan anti-debug/DRM as found in FromSoftware titles
-
eryx-precompile
CLI tool for pre-compiling eryx WASM runtimes
-
allow-match
Finding-to-policy matching and lifecycle classification for cargo-allow
-
bw-picker
CLI tool used to fetch passwords and more from Bitwarden using their Vault API
-
linux-audit-parser
Parser for Linux Audit logs
-
cve-data
Request CVE data from different sources
-
malina
Create replicable and unique malware analysis laboratories from configuration
-
ocsf-types
Strongly typed Rust structs for the OCSF (Open Cybersecurity Schema Framework)
-
dicgen
Generate a list with all combinations for given characters, like in brute force attacks
-
orcs-app
ORCS Application Layer - Re-exports and AppError
-
security_core
Shared security types, identity traits, correlation context, and data classification primitives
-
passcore
lightweight Rust library that scores password strength
-
mini-vet
A client for the cargo-vet registry. Fetches security reviews for Rust/Cargo crates.
-
cf-credstore
credstore gateway module
-
ghastoolkit
GitHub Advanced Security Toolkit in Rust
-
petriage
Cross-platform PE file surface analysis tool for malware analysts
-
ssec-cli
command-line interface for reading and writing the SSEC file format
-
uwd
Call Stack Spoofing for Rust
-
virtual_exec
A sandbox execution environment which allowed limited execution of expression safely (WIP)
-
daytona
Rust SDK for Daytona — secure sandboxes for AI code execution
-
goran
CLI tool for analyzing domains and IP addresses
-
arcbox-vm
Guest-side Firecracker sandbox manager (frozen; see arcbox-vmm for host VMM)
-
sbom-walker
work with SBOM data
-
secret-manager
A distributed secret rotation and management library
-
gen-secattest
gen — the Security-Attestation (SecAttest) INVARIANT contract. The universal typed law that every derivation carries a COMPLETE, content-addressed, FAIL-CLOSED security verdict {signature…
-
mintrt
Security-featured runtime for lua
-
nessus-parser
A parser for
.nessus(v2) XML reports -
xgadget
Fast, parallel, cross-variant ROP/JOP gadget search for x86/x64 binaries
-
phishnano
Lightweight offline phishing URL detection library with embedded Random Forest model, microsecond local inference, and zero network requests
-
sandbox-run
Cross-platform process sandboxing (Linux Landlock, macOS SBPL) via pre_exec
-
packguard-intel
PackGuard vulnerability intel: OSV + GHSA fetchers, parsers, dedup
-
vvva_permissions
Capability-based permission sandbox for the 3va JavaScript runtime — deny-by-default with interactive prompts and audit logging
-
rma-parser
Tree-sitter based polyglot parser for Qryon
-
skeld
a TUI tool for opening projects inside a restricted sandbox
-
haruspex
Vulnerability research assistant that extracts pseudocode from IDA Hex-Rays decompiler
-
ghidra-version-manager
Ghidra Version Manager
-
test_kms_server
Run a test KMS server for testing purposes
-
cvssrust
Common Vulnerability Scoring System (v2 / v3.0 / v3.1)
-
oneiromancer
Reverse engineering assistant that uses a locally running LLM to aid with pseudocode analysis
-
atlas-detect
MITRE ATLAS technique detection for LLM and AI agent security. Detects prompt injection, jailbreaks, credential exfiltration, model extraction, and 90+ other AI-specific attack techniques.
-
secretscan
A blazing-fast secret scanner for your codebase
-
harbor-core
Core library for the Harbor tool
-
skill-harness
Lifecycle management for AI agent skills — install, audit, eval, sync across environments
-
path_ratchet
Prevent path traversal attacks at type level
-
endpoint-sec-sys
Raw Rust wrappers around the Endpoint Security Framework
-
malwaredb-client
Client application and library for connecting to MalwareDB
-
mace
Automated extration of malware configuration, focusing on C2 communication
-
uv-audit
internal component crate of uv
-
floss-cli
在 Rust 中以子进程方式调用 FLARE FLOSS CLI,并可选解析 -j JSON 输出
-
hash-hunter
Find files with specified hashes
-
mwemu
x86 32/64bits and system internals emulator, for securely emulating malware and other stuff
-
rusty-sandbox
-
seccompy
Seccomp library with unotify support and without libseccomp dependency
-
drupal_cracker
This project is a very basic password cracker that cracks Drupal 7, 8, 9, 10, and 11 password hashes from a dictionary of passwords
-
zorph-crypto
Cryptographic primitives for the Zorph platform
-
lds-sandbox
Sandbox module for local-develop-server (lds) — file-scoped read/append with snapshot and rollback
-
onetimepassword
One-Time Password implementations
-
assemblyline-filestore
A blob storage layer for the Assemblyline malware analysis platform
-
subhunter
Ferramenta avançada de enumeração de subdomínios para Bug Bounty e Pentest
-
ry-god
Industrial-grade security & efficiency framework for Ry-Dit. Sandboxed execution, audit logging, memory limits, and zero-crash guarantees.
-
mimobox-vm
MimoBox microVM sandbox backend using Linux KVM
-
swink-agent-policies
Policy implementations for swink-agent
-
security-mcp
MCP (Model Context Protocol) server providing security screening, injection detection, and threat analysis
-
aios-sandbox
Execution sandboxing for Agent OS tool invocation
-
llm-security
Comprehensive LLM security layer to prevent prompt injection and manipulation attacks
-
rsrp-proof-engine
Deterministic proof engine for high-integrity Rust applications
-
falco_plugin_runner
Pure-Rust runner for Falco plugins
-
rite-ls
Language server for the Rite ceremony DSL
-
yedad_entropy
Deterministic wallet entropy pipeline for Yadad with full security features
-
toolpath-codex
Derive Toolpath provenance documents from Codex CLI session logs
-
fierros-guardrails
Fail-closed guardrail and runtime policy primitives for Fierros
-
sublime_pkg_tools
Package and version management toolkit for Node.js projects with changeset support
-
metactld
metactl v2 local reference-kernel JSON-RPC/MCP shim
-
cargo-caps
Audit what a crate is capable of by analyzing what linker symbols it emits
-
idalib-build
Idiomatic bindings to IDA SDK
-
rotaryoss-core
Core types and traits for the Rotary secret health auditor
-
threatflux-string-analysis
Deterministic, configurable string analysis primitives for security tooling
-
shellcode-loader
shellcode加载器,通过多种方式加载shellcode并对抗EDR检测
-
rma-indexer
Tantivy/Sled based indexing for Qryon
-
dlopen-note
ELF .note.dlopen metadata
-
dome-gate
Interceptor chain orchestration for Thunder Dome
-
wef
embedding WebView functionality using Chromium Embedded Framework (CEF3) with offscreen rendering support
-
sn0int-common
sn0int - common code
-
cf-gears-credstore-sdk
SDK for credstore gear: API traits, models, and error definitions
-
cosmian_kms_client
Cosmian KMS REST Client
-
palisade-telemetry
Telemetry and monitoring engine for the Palisade honeypot system
-
packguard-store
PackGuard SQLite store: migrations, persistence, fingerprinting
-
corcept-sink-cloudevents
CloudEvents 1.0 projection for CORCEPT ledger audit events
-
rustnmap-scan-management
Scan management for RustNmap (persistence, diff, YAML profiles)
-
car-runtime
Umbrella entry point for external Rust consumers of Common Agent Runtime
-
scanr-sca
SCA engine implementation for Scanr
-
get-capec
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
gpl-license-guard
License-boundary inspection gate: scans a repo/package for GPL/GNU boundary surfaces (vendored source, bundled binaries, library linking, crate licenses) and emits a fail-closed compliance…
-
terminal-commanderd
Long-running Terminal Commander daemon. Owns bucket manager, context spool, policy engine, audit emitter, and local API.
-
euvd
API for querying recent vulnerabilities from the ENISA EUVD database
-
shavee_pam
shavee is a program to automatically decrypt and mount ZFS datasets using Yubikey HMAC as 2FA or any USB drive with support for PAM to auto mount home directories
-
catsploit
An open-source modern exploitation framework inspired by Metasploit
-
uvb-audit-logging
Event and audit trail logging for UVB authentication operations
-
uvb-compliance
Regulatory compliance enforcement (NIST 800-63B, SOC 2, PCI DSS) for UVB
-
rust-metasploit
Rust wrapper for metasploit
-
shellforge
a highly customizable crate for generating assembly noops and junk code
-
hakoniwa-cli
Process isolation for Linux using namespaces, resource limits, cgroups, landlock and seccomp
-
leucite
sandboxing and limiting command execution
-
syara-x-capi
C API for syara-x
-
openvet-audit
Validation and check logic for OpenVet audits
-
malwaredb-virustotal-bin
VirusTotal command line client
-
safe-run
A lightweight sandbox for Linux using Landlock and Seccomp
-
agent-runbooks
Convention and validation for AI agent runbooks
-
nyx-agent-types
Implementation-detail serde and TypeScript wire types shared by nyx-agent crates
-
mine
High-assurance IPC and private Unix Domain Socket (UDS) orchestration. Provides exclusive data ownership and sandboxing for the Honest-Classified security ecosystem.
-
adaclaw-security
Lightweight, secure, multi-channel Rust AI Agent Runtime
-
fleetreach-maven
Maven (Java) ecosystem feeder for fleetreach: toolchain-free gradle.lockfile/pom.xml + OSV matching into the shared finding model
-
ripgen
A rust-based version of the popular dnsgen python utility
-
passgenz
A secure password generator CLI tool for macOS with clipboard integration
-
lockrail-relay
Policy-enforcing relay with replay protection for Lockrail
-
crevette
Converter for using cargo-crev reviews with cargo-vet
-
cleanlib-client
HTTP client SDK for the CleanLibrary verdict API — VerdictEnvelopeV1 types, derive_status logic, transport, config, and risk-acceptance YAML emitter shared between cleanlib-cli and other CleanLibrary consumers
-
dome-ledger
Hash-chained audit logging with multiple sinks for Thunder Dome
-
swage-pfn
PFN allocator module for Swage
-
touched
writing fuzzing harnesses of callback-style and trait-style Rust crates
-
lockrail-audit
Tamper-evident audit chain primitives for Lockrail
-
bucketwarden-server
BucketWarden storage server runtime
-
rsleigh-gen-arm32
rsleigh generated decoder for ARM32 (internal — use rsleigh-api)
-
malakit
dynamic analysis toolkit for Windows
-
u-siem-paloalto
be used to build a custom SIEM with the framework uSIEM
-
ppfuzz
| x | x | / _..___ | | | | | |/ // / || || ||`//_/ Prototype Pollution Fuzzer @dwisiswant0
-
harbor-cli
The Harbor CLI, which is a web security tool
-
fw-rs
A forensic-grade file destruction utility for securely overwriting and deleting files/directories
-
reinhardt
A focused security scanner for Django applications
-
cf-credstore-sdk
SDK for credstore module: API traits, models, and error definitions
-
parascope
Weggli ruleset scanner for source code and binaries
-
bmux_sandbox_harness
Reusable sandbox harness for bmux examples and tests
-
auditable
Audit Rust binaries for known bugs or vulnerabilities in production with zero bookkeeping
-
utimaco_pkcs11_loader
Utimaco HSM PKCS#11 loader
-
rustnmap-vuln
Vulnerability intelligence for RustNmap (CVE/CPE, EPSS, CISA KEV)
-
reoxide
Rust-bindings for the ReOxide decompiler extension framework
-
totally-safe
that allows you to bypass Rust's safety guarantees with totally safe patterns, featuring arbitrary lifetimes, aliasing, and more!
-
abcdict
A better customization password dictionary generator implementation by Rust
-
revolt_clamav-client
ClamAV client library
-
rite-model
Domain model and intermediate representation for the Rite key ceremony DSL
-
threat-intel
Comprehensive threat intelligence framework with multi-source aggregation, CVE integration, and risk assessment
-
smith-protocol
Shared protocol definitions for agent execution system
-
nyx-agent-sandbox
Implementation-detail sandbox runners used by nyx-agent verification and replay tasks
-
hypnus
Memory Obfuscation in Rust
-
packguard-server
PackGuard HTTP server: REST API + job runner backing the dashboard
-
lockb-xray
CLI tool to audit Bun bun.lockb for supply chain risks
-
rsleigh-fid
Function ID database — Ghidra FID-compatible function fingerprinting in pure Rust
-
mantid
multitool for security research and development
-
libsla-sys
System crate for Ghidra Sleigh library libsla
-
sentinel-sdk
Rust SDK for Sentinel LLM Security Gateway
-
augur
Reverse engineering assistant that extracts strings and related pseudocode from a binary file
-
jsrs
fast and flexible command-line tool for scanning JavaScript files
-
hexora
Static analysis of malicous Python scripts
-
u-siem-sqlite-store
be used to build a custom SIEM with the framework uSIEM
-
tekstide-core
Core domain, security, project, and content models for Tekstide
-
clamav-tcp
ClamAV TCP client
-
fenir
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
cargo-pants
cargo subcommand application that provides a bill of materials and a list of which dependencies have a vulnerability, powered by Sonatype OSSIndex
-
rustclr
Host CLR and run .NET binaries using Rust
-
cargo-vet
Supply-chain security for Rust
-
reaction-plugin
Plugin interface for reaction, a daemon that scans logs and takes action (alternative to fail2ban)
-
palisade-deception
Deception engine for the Palisade honeypot system - creates and manages honeytokens and decoy artifacts
-
jopcall
Dynamically executed Windows Syscalls via JOP/ROP
-
debian-repro-status
Check the reproducibility status of your installed Debian packages
-
clamd-client
Rust async tokio client for clamd. Works with a tcp socket or with the unix socket. At the moment it will open a new socket for each command. Work in progress.
-
Malware_Rhapsody
Small researching of Linux's security for fun and education.. don't be silly to use it in wild. Have a great day, Dear Researcher/Scholar 💯❤️
-
tayvo_clamav-client
ClamAV client library
-
ShellcodeGenerator
A shellcode generator for quickly exploit development
-
swage-victim-dev-memcheck
DevMemCheck victim module for Swage
-
ricecoder-teams
Team collaboration system for RiceCoder - shared standards, rule promotion, and access control
-
yara-forge
A powerful Rust library for crafting, validating, and managing YARA rules
-
envy-rs
Generate obfuscated Windows PowerShell payloads that resolve to paths by globbing environment variables
-
cosmian_kms_server
Cosmian Key Management Service - A high-performance, FIPS 140-3 and KMIP compliant Key Management System
-
tiny-vsock
Tiny vsock library for secure communication with enclaves
-
packguard-actions
PackGuard Page Actions engine: generates prioritized remediation actions from the store + policy + intel, with dismiss/defer persistence
-
pulsesecurity
Pulse Security SDK
-
fleetreach-ghactions
GitHub Actions ecosystem feeder for fleetreach: toolchain-free .github/workflows + OSV matching into the shared finding model
-
bp3d-os
Operating System tools designed for BlockProject3D
-
foundyou
A powerful command-line application for OSINT and social engineering
-
firewall_audit
Cross-platform firewall audit tool (YAML/JSON rules, CSV/HTML/JSON export)
-
airgorah
A WiFi security auditing software mainly based on aircrack-ng tools suite
-
gensense
High-performance semantic diagnostic engine for Rust, TypeScript, and Solidity
-
io-tubes
functionality like pwntools tube for async io in rust
-
rsrp-policy-dsl
Compiled policy DSL for deterministic access-control and proof-oriented rule execution
-
openvet-server
Reference HTTP server for hosting OpenVet logs
-
unicode-security
Detect possible security problems with Unicode usage according to Unicode Technical Standard #39 rules
-
logdog
A command-line tool for bug bounty hunters to log steps and capture terminal output
-
arkenar
CLI frontend for the Arkenar vulnerability scanner
-
nyx-agent-ai
Implementation-detail AI runtime adapters, prompts, and automation helpers for nyx-agent
-
mvm-security
Security modules for mvm: command gating, threat classification, rate limiting, posture scoring
-
version-checker
A clean, easy to use version checker built to help you track problems with your dependencies
-
nessus
Vulnerability Scanner API client
-
cvss_tools
working with CVSS
-
secbox
Sensitive data container
-
tartarus
CLI tool wrapping bubblewrap to run proccesses sandboxed to not be able to write to external directories
-
tnk
Zero-trust sandbox for local inference and secure AI coding agent runtimes
-
shinchina
tester
-
hardened-malloc
Global allocator using GrapheneOS allocator
-
cargo-cola
Security static analyzer for Rust. Analyzes MIR to detect vulnerabilities. (Requires nightly)
-
reverse_engineering_lib
reverse engineering tasks, including entropy calculation, color-based hex visualization, and PE file analysis
-
rust-mcp-server-syncable-cli
High-performance Model Context Protocol (MCP) server for code analysis, security scanning, and project insights
-
raxit-core
Core security scanning engine for AI agent applications
-
vtcode-safety
Command safety detection, execution policies, and sandboxing for VT Code
-
nvd_cve
Search for CVEs against a local cached copy of NIST National Vulnerability Database (NVD)
-
vein-admin
Admin web interface for Vein RubyGems proxy server
-
u-siem-sonicwall
be used to build a custom SIEM with the framework uSIEM
-
obfustring
Procedural macro that obfuscates string literals with RNG at compile time
-
cellos-host-cellos
Recursive CellOS-in-CellOS backend — runs CellOS cells as nested supervisors. Used for federated and self-hosting topologies.
-
rbacrab
Rust 🦀RBAC🦀 library with some crabby🦀🧙 macro magic! Blazingly 🚀🚀🚀 fast
-
ief
Cross-platform binary import/export search
-
judge-core
A judge library for online judge system
-
ntpsec-rs-mon
NTP monitor — forensic Rust reconstruction of ntpmon
-
skilllite-sandbox
SkillLite Sandbox: secure execution engine + environment builder
-
burn_operation
CLI tool to securely wipe a computer, at the speed of light
-
rustenium-identity
A versatile stealth overlay for rustenium
-
minosariane-shellforge
Terminal tool for generating reverse shells for CTF challenges and educational purposes. Easy to use, fast, and safe for practice environments.
-
macos-config-check
Checks your macOS machine against various hardened configuration settings
-
rappct
Rust AppContainer / LPAC toolkit for Windows (profiles, capabilities, process launch, diagnostics)
-
ankou
An OSINT repo miner focused on high-sev security bug in JS engines
-
bun-xray-core
Core parsing and security scanning logic for bun.lockb forensic analysis
-
mcpsec
MCP Security Benchmark Framework — vendor-neutral security evaluation for MCP gateways
-
rustshell
An educational project to aid in security operations and testing
-
zeph-tools
Tool executor trait with shell, web scrape, and composite executors for Zeph
-
clam-client
talking to ClamD
-
il2cpp_rs
interacting with il2cpp on Windows
-
camunda-orchestration-api-client
API for communicating with a Camunda 8 cluster. ## Conventions ### Enum value casing Server-side, enum-typed request fields accept any casing of a documented value (for example
ACTIVE… -
dna-rs
Async Rust client for the Domain Name API REST gateway
-
bmux_cli
Command-line interface for bmux terminal multiplexer
-
thehive-client
Rust client for TheHive API, enabling programmatic management of alerts, cases, observables, tasks, and other security incident response entities
-
fuguex
A binary analysis framework written in Rust
-
rust-doctor
A unified code health tool for Rust — scan, score, and fix your codebase
-
modseclog
Introspection of ModSecurity log files
-
sddl
parse and analyse SDDL Strings
-
lazycomposer
A TUI for managing PHP Composer dependencies, inspired by lazygit
-
polarstego
binary Steganographic Polar Codes
-
kastellan-sandbox
Cross-platform sandbox abstraction: bwrap+Landlock+seccomp on Linux, sandbox-exec (Seatbelt) on macOS
-
cargo-capsec
Static capability audit for Rust — find out what your code can do to the outside world
-
rite-sdk
Backend traits and domain types for the Rite cryptographic key ceremony toolkit
-
reoxide-proc
Proc-macro utility create for the ReOxide Rust-bindings
-
roche-daemon
Universal sandbox orchestrator for AI agents — gRPC daemon
-
confinery-sandbox
Platform sandbox engine for Confinery: namespaces, seccomp, Landlock, Job Objects
-
sublime_node_tools
Node.js bindings for Sublime Workspace CLI Tools via napi-rs
-
fosr
Fos-R (Forger Of Security Records) is an AI-based synthetic network traffic generator
-
tcp_reverse_shell
Creates a reverse shell (default to localhost:4444)
-
guardrails-mcp-server
AI agent guardrails MCP server -- input validation, output filtering, policy enforcement, audit logging
-
heel
Cross-platform native sandboxing library for running untrusted code
-
kindly-guard-cli
Command-line security scanner and monitoring tool for threat detection
-
cylo
Secure multi-language code execution service
-
hipcheck-common
Common functionality for the Hipcheck gRPC protocol
-
ferrous-forge
System-wide Rust development standards enforcer
-
higgs
Quantum-safe cryptography library with hybrid post-quantum algorithms. Features ML-KEM-768 (Kyber), ML-DSA-65 (Dilithium), X25519, ChaCha20-Poly1305, Argon2, and Shamir Secret Sharing for social recovery.
-
purl_validator
Offline PackageURL validator using a prebuilt FST of known packages
-
proteus-engine
Advanced zero-day static analysis engine built with Rust and Python
-
path_jail
A secure filesystem sandbox. Restricts paths to a root directory, preventing traversal attacks.
-
token-privilege
Safe Rust wrapper around Windows process token privilege and elevation detection APIs
-
get-cwe
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
droidsaw
— unified Android reverse engineering CLI. Hermes, DEX, APK signing. JSON output, MCP server. Bytecode is not a security layer.
-
skp-validator-actix
Actix Web integration for skp-validator - high-performance validation for Actix services
-
sandbox-scan
Security scan pipeline (YARA + heuristics + compose + ClamAV) for the sandbox CLI
-
ExploitBuilder
A exploit builder for quick exploit development
-
dlna-dmr
An extensible DLNA DMR (Digital Media Renderer) implementation
-
smtpeek
A state-of-the-art SMTP user enumeration tool that efficiently tests for valid email accounts on SMTP servers while evading detection mechanisms
-
secunit-capture
Native upstream capturers for secunit (gated behind cargo features)
-
misp-client-rs
client library for interacting with MISP (Malware Information Sharing Platform) instances via their REST API
-
skp-ratelimit
Advanced, modular, extensible rate limiting library with GCRA, per-route quotas, and composite keys
-
aws-sdk-inspector2
AWS SDK for Inspector2
-
inspektr_cli
A software composition analysis (SCA) tool for generating Software Bills of Materials (SBOM) and scanning for known vulnerabilities
-
swage-dummy
Dummy hammerer module for Swage
-
coffeeldr
A COFF (Common Object File Format) loader written in Rust
-
virustotal-rs
Rust SDK for VirusTotal API v3
-
ateam
that helps optimize the code review process
-
http_desync_guardian
HTTP/1.1 request analysis to prevent HTTP Desync attacks
-
vt3
VirusTotal REST API v3 (Public & Enterprise)
-
pysentry
Security vulnerability auditing for Python packages
-
parlov-elicit
Elicitation engine: strategy selection and probe plan generation for parlov
-
hanzo-sandbox
OS-level sandbox for subprocesses spawned by hanzo (code execution, tools)
-
vtcode-process-hardening
Process hardening and security measures for VT Code
-
shavee_core
shavee is a program to automatically decrypt and mount ZFS datasets using Yubikey HMAC as 2FA or any USB drive with support for PAM to auto mount home directories
-
gem-audit
Ultra-fast, standalone security auditor for Gemfile.lock
-
supply_poc_again
useless code to test supply chain attacks with cargo and crates.io
-
cargo-panic-audit
Find panic patterns that can take down production Rust services
-
winaudit
Advanced Windows auditing and security assessment Crate in Rust
-
check_txt
A powerful file security checker for TXT and EPUB files with virus scanning capabilities
-
swh-vulns-grpc-server
Mine data from vulnerability databases in the OSV format
-
codedefender-config
Configuration utilities for CodeDefender, a code obfuscation and protection system
-
nvd-api
A rust implementation of the nvd-api
-
sail-rs
Official Rust SDK for Sail: create and drive sailboxes (sandboxed cloud VMs) with lifecycle, streaming exec, file transfer, and ingress
-
pdf-perm
Change the permissions of a PDF file
-
zed-highlight-lsp
An LSP implemented for Zed that allows to highlight all occurrences of selected words
-
pctx_executor
TypeScript execution environment orchestration
-
fleetreach-scan
All rustsec interaction: query advisories and map engine types to core
-
cosmian_kms_server_database
containing the database for the Cosmian KMS server and the supported stores
-
introspectme
GraphQL schema reconstruction via field suggestion error analysis
-
luars
lua 5.5 runtime implementation in Rust
-
ancaptcha
Stateless human verification engine using interactive CSS instead of JavaScript
-
assemblyline-markings
using access control strings with the Assemblyline malware analysis platform
-
ntpsec-rs-time
NTP kernel time management — forensic Rust reconstruction of ntptime
-
nyx-agent-nyx
Implementation-detail subprocess driver for the upstream nyx static scanner
-
cpex-plugin-audit-logger
CPEX CMF plugin — structured per-request audit logging
-
cvss-rs
representing and deserializing CVSS (Common Vulnerability Scoring System) data
-
auditable-serde
Serialize/deserialize data encoded by
cargo auditable -
safebrowsing-api
Client for Google Safe Browsing API v4
-
phptaint
Security-focused PHP lexer, parser, AST, and configurable taint analysis engine
-
cwe-api-cli
Unofficial CLI for the CWE API
-
cargo-report
Generate reports for integration with external software
-
mur-core
Core library for MUR Commander: types, constitution, audit, model routing, and workflow engine
-
ricecoder-github
GitHub integration for repository operations
-
prudent-macros-lint
prudent-rs internal. Don't use directly/on its own. Instead, see and use prudent.
-
rsrp-security-core
Security primitives for deterministic proof systems (hashing, signatures, Merkle helpers)
-
llm-request-log
Structured log of LLM API requests with IDs, timing, and token counts
-
nono
Capability-based sandboxing library using Landlock (Linux) and Seatbelt (macOS)
-
clawbox
Sandboxed agent execution service — secure containers for externally-facing AI agents
-
idalib-sys
Idiomatic bindings to IDA SDK
-
mcp-supplier
Supplier MCP Server — a Supplier Relationship Management platform (suppliers, contacts, certifications & qualification, catalog & pricing, purchase orders, RFQ/sourcing, quality audits & SCARs…
-
iptr-edge-analyzer
Extract edges and branches in Intel PT traces, and construct AFL++-compatible fuzzing bitmaps
-
ingredients
Check ingredients of published Rust crates
-
telnet-sanitizer
Telnet TCP proxy that sanitizes protocol input to mitigate CVE-class vulnerabilities
-
brainwires-permission
Permission policies, audit logging, and trust profiles for the Brainwires Agent Framework
-
sleigh-compiler
Rust bindings for the Ghidra SLEIGH compiler. Used to compile processor .slaspec files into .sla files
-
sqlmap-rs
Type-safe asynchronous wrapper for the sqlmap REST API (sqlmapapi) with task lifecycle control and multi-format results
-
libsyd
Rust-based C library for syd interaction via /dev/syd
-
muthr
Runtime management CLI
-
escudo
Lightweight supply chain security checker for Rust
-
sbomr
Terminal UI for browsing CycloneDX and SPDX SBOM files
-
rbat
A terminal-native binary analysis tool for security researchers and reverse engineers
-
openvet-mirror
Validating mirror for OpenVet logs
-
cosmian_kms_crypto
Cosmian KMS Crypto - cryptographic operations and algorithms
-
path-security
Comprehensive path validation and sanitization library with 85%+ attack vector coverage
-
win_mitigations
Windows process mitigation policies
-
cedrus-cedar
Core library for Cedar Policy serialization and type bindings
-
bux-bwrap
Bundles the bubblewrap (bwrap) sandbox binary for bux — Linux-only process isolation
-
oalacea-warden
AI-powered security review CLI tool for web applications. Part of the Oalacea Security Suite. 100% Rust, zero dependencies.
-
drop-root-caps
drop 'root' user capabilities on Linux
-
nmap-helper
Some utilities for working with Nmap scan results (https://nmap.org)
-
louke
漏刻 (Louke) — the runtime observation dimension of Tianheng: declare which concrete-type origins may cross a runtime seam, probe live dyn objects in production fail-closed, react as a structured event (panic opt-in)…
-
forge-core-executors
Task executors for the Forge framework - handles task lifecycle and execution
-
fuguex-machine
A binary analysis framework written in Rust
-
cordance-advise
Cordance advisory engine. Deterministic doctrine checks against project state.
-
toolpath-pi
Derive Toolpath provenance documents from Pi (pi.dev) coding-agent session logs
-
vervet-technique
The Technique trait contract and self-registering inventory of emulation primitives
-
buildfix-receipts-cargo-sec-audit
Adapter that parses cargo-sec-audit JSON output and converts it to buildfix receipts
-
agentd
Agent daemon for secure capability execution with pluggable isolation backends
-
drun-core
Sandboxed execution core for drun
-
tartarus-api
Structured API for sandboxing system (currently utilizing
bubblewrap) -
orchestrator-scheduler
Task scheduler engine for the Agent Orchestrator
-
nvd-cwe
A rust implementation of the nvd-cwe
-
rustnmap-stateless-scan
Stateless high-speed scanning for RustNmap (masscan-like)
-
cosmian_pkcs11
HSM PKCS#11 provider for Cosmian KMS
-
get-mitre
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
symbi
AI-native agent framework for building autonomous, policy-aware agents that can safely collaborate with humans, other agents, and large language models
-
sandbox-runtime
OS-level sandboxing tool for enforcing filesystem and network restrictions
-
lonkero
Web scanner built for actual pentests. Fast, modular, Rust.