Open highlighted repo slot
Put your repository first
Promote a GitHub repo at the top of Awesome repository list views for 7 days.
GitHub projects from awesome lists
Search names, descriptions, topics, tags, and stacks, then tune results by ecosystem, freshness, health, and cross-list signal.
Open highlighted repo slot
Promote a GitHub repo at the top of Awesome repository list views for 7 days.
The Fish Shell Framework
Linux/OSX/FreeBSD resource monitor
Fast subdomains enumeration tool for penetration testers
The Browser Exploitation Framework Project
Interactive cli tool for HTTP inspection
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
Exploit Development and Reverse Engineering with GDB & LLDB Made Easy
This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
Performance analysis tools based on Linux perf_events (aka perf) and ftrace
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.
A command-line hex viewer
:zap: From finding text to search and replace, from sorting to beautifying text and more :art:
High-level tracing language for Linux
List of awesome reverse engineering resources
Universal command-line interface for SQL databases
The pattern matching swiss knife
The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
A list of public penetration test reports published by several consulting firms and academic security groups.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
Some setup scripts for security research tools.
Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
DevOps Guide - Development to Production all configurations with basic notes to debug efficiently.
Testing TLS/SSL encryption anywhere on any port
Main gperftools repository
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
Malicious traffic detection system