The Vault
746 curated tools across 6 categories — auto-updated weekly
Showing all 746 tools
build-your-own-x
codecrafters-io/build-your-own-x
Hands-on tutorials for recreating popular technologies from scratch
awesome
sindresorhus/awesome
Meta collection of awesome lists covering all tech topics
freeCodeCamp
freeCodeCamp/freeCodeCamp
Comprehensive free coding curriculum and learning platform for programming fundamentals
free-programming-books
EbookFoundation/free-programming-books
Massive collection of free programming books and educational resources
openclaw
openclaw/openclaw
Cross-platform personal AI assistant framework with data ownership focus
awesome-python
vinta/awesome-python
Comprehensive list of Python frameworks, libraries and development resources
awesome-selfhosted
awesome-selfhosted/awesome-selfhosted
Comprehensive list of self-hostable network services and web applications
Python
TheAlgorithms/Python
Educational algorithm implementations for computer science and interview preparation
ohmyzsh
ohmyzsh/ohmyzsh
Community-driven zsh configuration framework with plugins and themes
n8n
n8n-io/n8n
Visual workflow automation platform with native AI capabilities and 400+ integrations
awesome-go
avelino/awesome-go
Curated list of Go frameworks, libraries and development resources
ollama
ollama/ollama
Local LLM runtime supporting multiple models including Qwen, Gemma, and DeepSeek
prompts.chat
f/prompts.chat
Community platform for sharing and discovering AI prompts and techniques
langflow
langflow-ai/langflow
Visual workflow builder for creating and deploying AI agents with drag-and-drop interface
next.js
vercel/next.js
Popular React framework for production web apps with SSR and static generation
system-prompts-and-models-of-ai-tools
x1xhlol/system-prompts-and-models-of-ai-tools
Collection of AI system prompts and models from popular coding tools
opencode
anomalyco/opencode
Open source coding agent for automated software development tasks
kubernetes
kubernetes/kubernetes
Production-grade container orchestration platform for modern applications
free-for-dev
ripienaar/free-for-dev
Free tier services for DevOps, development, and infrastructure
excalidraw
excalidraw/excalidraw
Collaborative virtual whiteboard for sketching diagrams and visual planning
ui
shadcn-ui/ui
Modern React component library with accessible design and framework flexibility
rustdesk
rustdesk/rustdesk
Self-hosted remote desktop alternative to TeamViewer with cross-platform support
godot
godotengine/godot
Multi-platform 2D/3D game engine for cross-platform development
frp
fatedier/frp
Fast reverse proxy for exposing local servers through NAT and firewalls
superpowers
obra/superpowers
Agentic skills framework for software development methodology with practical approach
awesome-mac
jaywcjlove/awesome-mac
Comprehensive collection of high-quality macOS software and tools
supabase
supabase/supabase
Open-source Postgres development platform with auth, real-time, and AI capabilities
skills
anthropics/skills
Official Anthropic repository for agent skills development and examples
whisper
openai/whisper
OpenAI's robust speech recognition system using large-scale supervision
immich
immich-app/immich
High-performance self-hosted photo/video management and backup solution
everything-claude-code
affaan-m/everything-claude-code
Agent harness optimization system for Claude Code with skills and memory management
nvm
nvm-sh/nvm
POSIX-compliant Node.js version manager for switching between Node versions
playwright
microsoft/playwright
Cross-browser testing framework for web automation and E2E testing
servers
modelcontextprotocol/servers
Official collection of Model Context Protocol servers for AI applications
uv
astral-sh/uv
Extremely fast Python package manager written in Rust for efficient dependency management
claude-code
anthropics/claude-code
Terminal-based AI coding assistant that understands codebases and handles git workflows
Deep-Live-Cam
hacksider/Deep-Live-Cam
Real-time deepfake and face swap tool using AI for video manipulation
spec-kit
github/spec-kit
GitHub toolkit for spec-driven development with AI integration
zed
zed-industries/zed
High-performance multiplayer code editor built in Rust by Atom creators
cs-video-courses
Developer-Y/cs-video-courses
Curated list of computer science courses with video lectures covering various topics
code-server
coder/code-server
VS Code running in browser for remote development environments
elasticsearch
elastic/elasticsearch
Distributed RESTful search and analytics engine for enterprise data solutions
PayloadsAllTheThings
swisskyrepo/PayloadsAllTheThings
Curated payload collection for web app security testing and CTF challenges
Ventoy
ventoy/Ventoy
Multi-boot USB solution supporting various OS images and secure boot
lazygit
jesseduffield/lazygit
Simple terminal UI for Git commands with visual interface
sherlock
sherlock-project/sherlock
Social media account hunting by username across multiple platforms
tesseract
tesseract-ocr/tesseract
Industry-standard OCR engine for extracting text from images and documents
moby
moby/moby
Core Docker project for container-based system development and deployment
caddy
caddyserver/caddy
Fast multi-platform web server with automatic HTTPS and reverse proxy capabilities
SecLists
danielmiessler/SecLists
Comprehensive collection of security testing wordlists and payloads for pentesting
ansible
ansible/ansible
Agentless IT automation platform for configuration management and deployment
codex
openai/codex
Lightweight terminal-based coding agent from OpenAI
ghidra
NationalSecurityAgency/ghidra
NSA's powerful software reverse engineering framework and disassembler
localstack
localstack/localstack
Local AWS cloud stack emulator for offline development and testing
prometheus
prometheus/prometheus
Industry-standard time series database and monitoring system for infrastructure metrics
traefik
traefik/traefik
Cloud-native application proxy and load balancer with automatic service discovery
nerd-fonts
ryanoasis/nerd-fonts
Massive collection of developer-focused patched fonts with programming icons
ladybird
LadybirdBrowser/ladybird
Independent web browser engine built from scratch for security and performance
cline
cline/cline
Autonomous coding agent for IDEs with file creation and command execution
agency-agents
msitarzewski/agency-agents
Complete AI agency framework with specialized agents for different business roles
astro
withastro/astro
Modern web framework for content-driven static and hybrid sites
html5-boilerplate
h5bp/html5-boilerplate
Professional HTML5 boilerplate with best practices for robust web development
vaultwarden
dani-garcia/vaultwarden
Self-hosted password manager, essential for secrets management
pi-hole
pi-hole/pi-hole
Network-wide ad blocker with DNS server and DHCP capabilities
nanoGPT
karpathy/nanoGPT
Karpathy's minimal GPT training implementation, perfect for learning and experimentation
starship
starship/starship
Fast, customizable shell prompt that works across multiple shells
ChatGPT
lencx/ChatGPT
Cross-platform ChatGPT desktop app with note-taking features
powerlevel10k
romkatv/powerlevel10k
Fast and feature-rich zsh theme for enhanced terminal experience
ImHex
WerWolv/ImHex
Feature-rich hex editor with pattern analysis for reverse engineering
Docker-OSX
sickcodes/Docker-OSX
Run macOS VM in Docker containers for CI/CD and security research
lazydocker
jesseduffield/lazydocker
Simple terminal UI for managing Docker containers and images
nanochat
karpathy/nanochat
Budget-conscious ChatGPT alternative optimized for cost efficiency
winutil
ChrisTitusTech/winutil
Windows system administration utility for tweaks, updates, and software management
autoresearch
karpathy/autoresearch
Karpathy's autonomous research AI agents for single-GPU training experiments
terraform
hashicorp/terraform
Infrastructure as code tool for safely managing cloud resources
open-source-mac-os-apps
serhii-londar/open-source-mac-os-apps
Curated list of open source macOS applications for developers
ui-ux-pro-max-skill
nextlevelbuilder/ui-ux-pro-max-skill
AI skill for professional UI/UX design intelligence across multiple platforms
serverless
serverless/serverless
Popular framework for building auto-scaling serverless applications on cloud platforms
awesome-compose
docker/awesome-compose
Collection of Docker Compose examples for development and deployment
helix
helix-editor/helix
Modern modal text editor in Rust, alternative to Vim with improved ergonomics
RSSHub
DIYgod/RSSHub
Universal RSS hub converting various platforms to RSS feeds for content aggregation
Files
files-community/Files
Modern Windows file manager with developer-friendly features and Git integration
BMAD-METHOD
bmad-code-org/BMAD-METHOD
Agile AI-driven development methodology framework
ccxt
ccxt/ccxt
Comprehensive cryptocurrency trading API library supporting 100+ exchanges
desktop
zen-browser/desktop
Privacy-focused Firefox-based browser for secure web browsing and development
cal.com
calcom/cal.com
Open-source scheduling platform built with modern TypeScript stack
awesome-openclaw-skills
VoltAgent/awesome-openclaw-skills
Curated collection of 5400+ OpenClaw agent skills categorized and filtered
Fabric
danielmiessler/Fabric
Modular AI framework with crowdsourced prompts for human augmentation
litellm
BerriAI/litellm
Universal LLM API gateway with cost tracking and guardrails for 100+ providers
claude-mem
thedotmack/claude-mem
Claude Code plugin for AI-powered memory and context injection in coding
MiroFish
666ghj/MiroFish
Multi-agent swarm intelligence engine for prediction and social analysis
get-shit-done
gsd-build/get-shit-done
Meta-prompting framework for Claude Code with spec-driven development approach
metasploit-framework
rapid7/metasploit-framework
The legendary Metasploit penetration testing and exploitation framework
cli
httpie/cli
Modern command-line HTTP client with JSON support, colors, and developer features
it-tools
CorentinTh/it-tools
Collection of handy online tools for developers with great UX
paperless-ngx
paperless-ngx/paperless-ngx
Document management system with OCR and machine learning capabilities
sqlmap
sqlmapproject/sqlmap
Automated SQL injection detection and database takeover tool
headscale
juanfont/headscale
Open source self-hosted Tailscale control server implementation
reactive-resume
amruthpillai/reactive-resume
Privacy-focused resume builder with modern tech stack, useful dev tool
gstack
garrytan/gstack
Opinionated Claude Code setup for CEO, Designer, Eng Manager roles
awesome-docker
veggiemonk/awesome-docker
Comprehensive list of Docker resources, tools and projects
learn-claude-code
shareAI-lab/learn-claude-code
Educational Claude Code agent harness built from scratch for learning AI agents
vault
hashicorp/vault
Enterprise secrets management and privileged access management platform
Trilium
TriliumNext/Trilium
Self-hosted personal knowledge management system with note-taking features
LibreChat
danny-avila/LibreChat
Enhanced ChatGPT clone with multiple AI providers and agent capabilities
system_prompts_leaks
asgeirtj/system_prompts_leaks
Collection of extracted system prompts from popular AI chatbots for research
croc
schollz/croc
Secure peer-to-peer file transfer tool with end-to-end encryption
server
nextcloud/server
Self-hosted cloud platform for file sharing and collaboration
pnpm
pnpm/pnpm
Fast, disk-efficient package manager alternative to npm for Node.js development
CyberChef
gchq/CyberChef
Swiss Army knife for data analysis, encryption, encoding - essential security tool
filebrowser
filebrowser/filebrowser
Web-based file browser for server management and file operations
trivy
aquasecurity/trivy
Comprehensive vulnerability scanner for containers, Kubernetes, code, and clouds
CasaOS
IceWhaleTech/CasaOS
Self-hosted personal cloud OS with Docker containerization and home automation
awesome-sysadmin
awesome-foss/awesome-sysadmin
Curated collection of open-source system administration tools and resources
AdGuardHome
AdguardTeam/AdGuardHome
Network-wide DNS server blocking ads and trackers with privacy focus
k9s
derailed/k9s
Terminal-based Kubernetes cluster management tool with intuitive interface
web-check
Lissy93/web-check
All-in-one website analysis tool for OSINT investigations and reconnaissance
nginx-proxy-manager
NginxProxyManager/nginx-proxy-manager
Docker container for managing Nginx proxy hosts with web interface
posthog
PostHog/posthog
All-in-one developer platform with analytics, feature flags, and AI product assistant
glances
nicolargo/glances
Cross-platform system monitoring tool with web API and terminal interface
sharp
lovell/sharp
High-performance Node.js image processing library using libvips
cockroach
cockroachdb/cockroach
Cloud-native distributed SQL database designed for high availability
agents
wshobson/agents
Multi-agent orchestration framework for Claude Code with intelligent automation
dokku
dokku/dokku
Docker-powered PaaS for building and managing application lifecycles, Heroku alternative
minikube
kubernetes/minikube
Local Kubernetes development environment for testing and learning
CheatSheetSeries
OWASP/CheatSheetSeries
OWASP cheat sheets covering essential application security topics and best practices
paperclip
paperclipai/paperclip
Open-source orchestration platform for autonomous business operations
podman
containers/podman
Daemonless container engine - secure Docker alternative for managing OCI containers
changedetection.io
dgtlmoon/changedetection.io
Website change detection and monitoring tool for content tracking and alerts
vscodium
VSCodium/vscodium
VS Code without Microsoft telemetry and licensing restrictions
awesome-claude-code
hesreallyhim/awesome-claude-code
Curated list of Claude Code skills, hooks, and agent orchestration resources
helm
helm/helm
The standard package manager for Kubernetes - essential for application deployment
Jobs_Applier_AI_Agent_AIHawk
feder-cr/Jobs_Applier_AI_Agent_AIHawk
AI-powered job application automation agent using GPT and web scraping
ntfy
binwiederhier/ntfy
Self-hosted notification service for developers to send push notifications via HTTP
github-mcp-server
github/github-mcp-server
GitHub's official Model Context Protocol server for AI integration
harbor
goharbor/harbor
Enterprise container registry with security scanning and content signing
nuclei
projectdiscovery/nuclei
Fast YAML-based vulnerability scanner for apps, APIs, networks, and cloud
authelia
authelia/authelia
Multi-factor SSO portal with OpenID certification and passkey support
ProxmoxVE
community-scripts/ProxmoxVE
Community scripts for Proxmox VE virtualization platform management
awesome-falsehood
kdeldycke/awesome-falsehood
Educational resource about programming pitfalls and common misconceptions
searxng
searxng/searxng
Privacy-focused metasearch engine aggregating results without tracking
pi-mono
badlogic/pi-mono
AI agent toolkit with coding CLI, unified LLM API, and web interfaces
Awesome-LLM
Hannibal046/Awesome-LLM
Comprehensive curated list of LLM resources, papers, and tools
AstrBot
AstrBotDevs/AstrBot
Multi-platform agentic chatbot infrastructure with LLM integration and plugins
mkdocs-material
squidfunk/mkdocs-material
Material Design theme and framework for MkDocs documentation sites
ungoogled-chromium
ungoogled-software/ungoogled-chromium
Privacy-focused Chromium browser with Google integrations and tracking removed
hashcat
hashcat/hashcat
World's fastest GPU-accelerated password recovery utility
awesome-pentest
enaqx/awesome-pentest
Comprehensive penetration testing tools and resources collection
gitleaks
gitleaks/gitleaks
Fast secrets detection tool with AI-powered analysis for Git repositories
awesome-osint
jivoi/awesome-osint
Comprehensive curated list of Open Source Intelligence (OSINT) tools and resources
ente
ente-io/ente
End-to-end encrypted cloud storage with zero-knowledge privacy protection
trufflehog
trufflesecurity/trufflehog
Find, verify, and analyze leaked credentials in code repositories and files
wg-easy
wg-easy/wg-easy
Easy WireGuard VPN deployment with web-based admin interface
nanoclaw
qwibitai/nanoclaw
Containerized AI assistant with multi-messenger support and memory
dashy
Lissy93/dashy
Self-hosted personal dashboard with monitoring widgets for homelab management
agent-browser
vercel-labs/agent-browser
Browser automation CLI specifically designed for AI agent workflows in Rust
cilium
cilium/cilium
eBPF-based container networking and security for Kubernetes environments
Scoop
ScoopInstaller/Scoop
Command-line package installer for Windows with bucket-based management
netbird
netbirdio/netbird
Secure WireGuard-based mesh network with SSO and access controls
vibe-kanban
BloopAI/vibe-kanban
Kanban-style task manager for enhancing Claude Code and coding agents
browser
lightpanda-io/browser
Headless browser specifically designed for AI automation and web scraping tasks
API-Security-Checklist
shieldfy/API-Security-Checklist
Essential security checklist for API design, testing, and deployment
slim
slimtoolkit/slim
Container image minification tool that reduces size by 30x while improving security
awesome-flipperzero
djsime1/awesome-flipperzero
Flipper Zero resources for hardware hacking and RF analysis
Roo-Code
RooCodeInc/Roo-Code
AI-powered development team integrated directly into code editors for assistance
dockge
louislam/dockge
Self-hosted Docker Compose stack manager with reactive web interface
macOS-Security-and-Privacy-Guide
drduh/macOS-Security-and-Privacy-Guide
Comprehensive macOS security hardening and privacy configuration guide
ruflo
ruvnet/ruflo
Agent orchestration platform for Claude with multi-agent swarms and RAG integration
UniGetUI
Devolutions/UniGetUI
Universal GUI for Windows package managers (winget, chocolatey, pip, scoop, npm)
SuperClaude_Framework
SuperClaude-Org/SuperClaude_Framework
Configuration framework enhancing Claude Code with specialized commands
mdBook
rust-lang/mdBook
Generate technical books from markdown files, Rust-based Gitbook alternative
sops
getsops/sops
Flexible secrets encryption tool supporting multiple cloud providers and PGP
renovate
renovatebot/renovate
Automated dependency updates across multiple platforms and package managers
dns-blocklists
hagezi/dns-blocklists
Comprehensive DNS blocklists for malware, ads, and malicious domain filtering
fastfetch
fastfetch-cli/fastfetch
Fast system information tool, maintained alternative to neofetch with better performance
CLI-Anything
HKUDS/CLI-Anything
Framework for making all software accessible to AI agents via CLI interfaces
awesome-readme
matiassingers/awesome-readme
Examples of excellent README documentation for projects
authentik
goauthentik/authentik
Identity provider with SAML, OAuth2, and OIDC support for authentication
awesome-tunneling
anderspitman/awesome-tunneling
Curated list of tunneling and self-hosted networking alternatives to ngrok
containerd
containerd/containerd
Industry-standard container runtime powering Docker and Kubernetes
claude-code-best-practice
shanraisshan/claude-code-best-practice
Best practices and patterns for Claude AI coding and prompt engineering
teleport
gravitational/teleport
Zero-trust access platform for infrastructure with certificate-based auth
netbox
netbox-community/netbox
Network automation and infrastructure management platform, essential for DevOps
Atlas
Atlas-OS/Atlas
Windows hardening and privacy modification toolkit for secure configurations
PEASS-ng
peass-ng/PEASS-ng
Privilege escalation enumeration scripts suite for Linux and Windows with colors
RustScan
bee-san/RustScan
High-speed Rust port scanner with modern features and Docker support
ingress-nginx
kubernetes/ingress-nginx
Official NGINX ingress controller for Kubernetes - handles external traffic routing
maigret
soxoj/maigret
Username enumeration across thousands of sites for OSINT investigations
hurl
Orange-OpenSource/hurl
Plain text HTTP testing tool for API testing and integration testing
GitNexus
abhigyanpatwari/GitNexus
Client-side code intelligence engine creating knowledge graphs with RAG agent
catppuccin
catppuccin/catppuccin
Meta repository for popular pastel theme across multiple development tools
GHunt
mxrch/GHunt
Offensive Google OSINT framework for gathering intelligence from Google services
Handy
cjpais/Handy
Open source offline speech-to-text application with accessibility features
awesome-privacy
pluja/awesome-privacy
Curated list of privacy-respecting services and alternatives
promptfoo
promptfoo/promptfoo
Comprehensive testing and red teaming framework for AI prompts and agents
docker-mailserver
docker-mailserver/docker-mailserver
Production-ready containerized mail server with antispam and antivirus
L1B3RT4S
elder-plinius/L1B3RT4S
AI jailbreak prompts for red teaming and adversarial testing of AI systems
linkwarden
linkwarden/linkwarden
Self-hosted collaborative bookmark manager with annotation capabilities
OpenViking
volcengine/OpenViking
Context database for AI agents with hierarchical memory and skill management
awesome-zsh-plugins
unixorn/awesome-zsh-plugins
ZSH plugins and themes for enhanced terminal productivity
nebula
slackhq/nebula
High-performance overlay networking tool for secure mesh networking
hydra
ory/hydra
Enterprise OAuth2/OIDC provider for identity management and secure authentication
open-gpu-kernel-modules
NVIDIA/open-gpu-kernel-modules
Open source NVIDIA GPU kernel modules for Linux development environments
Flipper
UberGuidoZ/Flipper
Custom modifications and tools for Flipper Zero hardware hacking device
codon
exaloop/codon
High-performance Python compiler with zero-overhead and GPU support
ZeroTierOne
zerotier/ZeroTierOne
Decentralized VPN creating secure virtual networks with peer-to-peer architecture
heretic
p-e-w/heretic
Automatic censorship removal tool for language models using abliteration techniques
nomad
hashicorp/nomad
Flexible workload orchestrator for deploying diverse application types at scale
katana
projectdiscovery/katana
Next-gen web crawling and spidering framework for reconnaissance and asset discovery
Seelen-UI
eythaann/Seelen-UI
Customizable Windows desktop environment with tiling window manager and modern UI
Signal-Desktop
signalapp/Signal-Desktop
Cross-platform encrypted messaging client for secure desktop communications
awesome-hacking
carpedm20/awesome-hacking
General hacking tutorials, tools and educational security resources
flipperzero-firmware
flipperdevices/flipperzero-firmware
Flipper Zero firmware for multi-tool hardware hacking and RF analysis
packer
hashicorp/packer
Multi-platform machine image builder for consistent deployment environments
answer
apache/answer
Open-source Q&A platform for building community forums and knowledge bases
awx
ansible/awx
Web UI and REST API for Ansible automation platform management
kind
kubernetes-sigs/kind
Local Kubernetes clusters in Docker for testing and development workflows
wazuh
wazuh/wazuh
Open source unified XDR and SIEM platform for endpoint and cloud protection
NemoClaw
NVIDIA/NemoClaw
Secure OpenClaw execution within NVIDIA OpenShell runtime with managed inference
faker
faker-js/faker
JavaScript library for generating realistic fake data for testing and development
zaproxy
zaproxy/zaproxy
OWASP ZAP core project - comprehensive web application security scanner
cryptomator
cryptomator/cryptomator
Client-side encryption tool for securing cloud storage files
logstash
elastic/logstash
Data processing pipeline for logs, events, and real-time streaming ETL operations
social-engineer-toolkit
trustedsec/social-engineer-toolkit
Comprehensive social engineering toolkit for security testing and red team operations
amass
owasp-amass/amass
Comprehensive attack surface mapping and asset discovery platform by OWASP
awesome-microservices
mfornos/awesome-microservices
Microservices architecture principles and technologies collection
awesome-security
sbilly/awesome-security
Comprehensive collection of security tools, resources, and documentation
coredns
coredns/coredns
Modular DNS server with plugin architecture for service discovery and resolution
CL4R1T4S
elder-plinius/CL4R1T4S
Leaked system prompts from major AI systems for transparency and security research
agentskills
agentskills/agentskills
Specification and documentation framework for standardizing AI agent skills
systeminformer
winsiderss/systeminformer
Advanced system monitor and debugging tool for Windows security analysis
cert-manager
cert-manager/cert-manager
Automated TLS certificate provisioning and management for Kubernetes clusters
gitpod
gitpod-io/gitpod
Cloud-based development environments for faster and more secure coding
awesome-malware-analysis
rshipp/awesome-malware-analysis
Malware analysis tools, frameworks and threat intelligence resources
gobuster
OJ/gobuster
Fast directory/file, DNS and VHost enumeration tool for discovering hidden resources
gluetun
qdm12/gluetun
Multi-provider VPN client container with DNS-over-TLS and proxy support
rook
rook/rook
Storage orchestration operator for Kubernetes - manages Ceph and other storage systems
prowler
prowler-cloud/prowler
Multi-cloud security platform for automated compliance and security auditing
Reverse-Engineering
mytechnotalent/Reverse-Engineering
Comprehensive reverse engineering tutorial covering multiple architectures
semaphore
semaphoreui/semaphore
Modern UI and API for Ansible, Terraform, and other DevOps tools
pwntools
Gallopsled/pwntools
Popular CTF framework and exploit development library with extensive tooling
subfinder
projectdiscovery/subfinder
Fast passive subdomain enumeration for reconnaissance and bug bounties
node_exporter
prometheus/node_exporter
System metrics exporter for Prometheus monitoring - essential for infrastructure visibility
awesome-web-security
qazbnm456/awesome-web-security
Curated web security materials and penetration testing resources
FlareSolverr
FlareSolverr/FlareSolverr
Proxy server to bypass Cloudflare protection for testing purposes
dnscrypt-proxy
DNSCrypt/dnscrypt-proxy
Encrypted DNS proxy supporting DoH, DNSCrypt for secure DNS resolution
page-agent
alibaba/page-agent
JavaScript in-page GUI agent for controlling web interfaces with natural language
Badges4-README.md-Profile
alexandresanlim/Badges4-README.md-Profile
Badge collection for improving GitHub profile documentation
john
openwall/john
Advanced offline password cracker supporting hundreds of hash types
crowdsec
crowdsecurity/crowdsec
Crowdsourced threat detection with shared CTI and malicious IP blocking
GTFOBins.github.io
GTFOBins/GTFOBins.github.io
Curated list of Unix binaries for bypassing security restrictions and privilege escalation
juice-shop
juice-shop/juice-shop
OWASP Juice Shop - intentionally insecure web app for security training and CTFs
aws-cdk
aws/aws-cdk
AWS CDK framework for defining cloud infrastructure as code in TypeScript
nitter
zedeus/nitter
Privacy-focused Twitter frontend alternative
nmap
nmap/nmap
Essential network discovery and port scanning tool for reconnaissance activities
Osintgram
Datalux/Osintgram
Instagram OSINT tool with interactive shell for account analysis
distrobox
89luca89/distrobox
Run any Linux distro in containers for development flexibility
PentestGPT
GreyDGL/PentestGPT
LLM-powered automated penetration testing framework for security assessments
portmaster
safing/portmaster
Application firewall and privacy protection tool for blocking network surveillance
dozzle
amir20/dozzle
Real-time Docker/K8s log viewer with web UI for container monitoring and debugging
nuclei-templates
projectdiscovery/nuclei-templates
Community-curated vulnerability templates for Nuclei scanner
vuls
future-architect/vuls
Agent-less vulnerability scanner for Linux, containers, and network devices
impeccable
pbakaus/impeccable
Design language framework for improving AI design capabilities and outputs
Signal-iOS
signalapp/Signal-iOS
Open-source encrypted messenger for iOS providing secure communications
shell_gpt
TheR1D/shell_gpt
Command-line productivity tool powered by GPT and other LLMs for task automation
grype
anchore/grype
Vulnerability scanner for container images and filesystems with SBOM support
thc-hydra
vanhauser-thc/thc-hydra
Fast network password cracker supporting many protocols and services
atomic-red-team
redcanaryco/atomic-red-team
Portable detection tests based on MITRE ATT&CK framework for threat detection
examples
serverless/examples
Collection of serverless architecture examples and boilerplates
netboot.xyz
netbootxyz/netboot.xyz
Network-based OS installer and provisioning tool using iPXE
netmaker
gravitl/netmaker
WireGuard-based mesh networking platform for secure distributed virtual networks
whoogle-search
benbusby/whoogle-search
Self-hosted ad-free privacy-respecting search engine alternative
linkerd2
linkerd/linkerd2
Lightweight service mesh providing security and observability for Kubernetes
kubescape
kubescape/kubescape
Kubernetes security platform with risk analysis, compliance, and misconfiguration scanning
hacktricks
HackTricks-wiki/hacktricks
Comprehensive wiki of hacking techniques, CTF tricks, and pentesting knowledge
docker-pi-hole
pi-hole/docker-pi-hole
Official Pi-hole Docker image for DNS-based ad blocking
sliver
BishopFox/sliver
Modern C2 framework for adversary emulation and red team operations
umbrel
getumbrel/umbrel
Self-hosted home server OS with 300+ apps including Bitcoin and cloud storage
terraform-provider-aws
hashicorp/terraform-provider-aws
Official AWS provider for Terraform infrastructure as code deployments
beef
beefproject/beef
Browser exploitation framework for testing web application security vulnerabilities
mRemoteNG
mRemoteNG/mRemoteNG
Multi-protocol remote connection manager for SSH, RDP, and other protocols
skopeo
containers/skopeo
Utility for working with container registries - inspect, copy, and sign images
Signal-Server
signalapp/Signal-Server
Backend server implementation for Signal encrypted messaging platform
awesome-hacker-search-engines
edoardottt/awesome-hacker-search-engines
Search engines for penetration testing and OSINT operations
linkding
sissbruecker/linkding
Self-hosted bookmark manager for developers and researchers
Personal_AI_Infrastructure
danielmiessler/Personal_AI_Infrastructure
Agentic AI infrastructure platform for augmenting human productivity and capabilities
sigma
SigmaHQ/sigma
Main repository for Sigma detection rules for SIEM and security monitoring
Betterfox
yokoffing/Betterfox
Optimized Firefox configuration for enhanced privacy, security, and performance
nikto
sullo/nikto
Classic web server scanner for identifying vulnerabilities and misconfigurations
Red-Teaming-Toolkit
infosecn1nja/Red-Teaming-Toolkit
Curated collection of open-source security tools for red teamers
bunkerweb
bunkerity/bunkerweb
Next-generation open-source Web Application Firewall with container support
obsidian-git
Vinzent03/obsidian-git
Git integration plugin for Obsidian with auto-commit and sync features
awesome-threat-intelligence
hslatman/awesome-threat-intelligence
Curated collection of threat intelligence resources and tools
healthchecks
healthchecks/healthchecks
Open-source cron job and background task monitoring service
jekyll-theme-chirpy
cotes2020/jekyll-theme-chirpy
Responsive Jekyll theme optimized for technical writing and documentation
buildkit
moby/buildkit
Advanced Docker builder toolkit with caching and concurrent build capabilities
httpx
projectdiscovery/httpx
Multi-purpose HTTP toolkit for probing and SSL certificate analysis
awesome-bash
awesome-lists/awesome-bash
Bash scripts and resources for shell scripting and automation
Sn1per
1N3/Sn1per
Comprehensive attack surface management platform with OSINT and pentesting tools
docker-bench-security
docker/docker-bench-security
Security benchmark script checking Docker container deployment best practices
bbot
blacklanternsecurity/bbot
Recursive internet scanner for attack surface management and reconnaissance
devops-resources
bregman-arie/devops-resources
Comprehensive DevOps resources covering cloud, containers, and security
terragrunt
gruntwork-io/terragrunt
Orchestration tool for scaling Terraform/OpenTofu infrastructure as code
VeraCrypt
veracrypt/VeraCrypt
Open-source disk encryption tool for securing data at rest with strong crypto algorithms
ctf-tools
zardus/ctf-tools
Setup scripts for security research and CTF tools collection
mitmproxy2swagger
alufers/mitmproxy2swagger
Automatically generates API docs from captured HTTP traffic using mitmproxy
awesome-privacy
Lissy93/awesome-privacy
Comprehensive curated list of privacy and security-focused tools and services
wireshark
wireshark/wireshark
Industry standard network packet analyzer for traffic monitoring and analysis
wstg
OWASP/wstg
OWASP's comprehensive guide to testing web application and service security
v2
miniflux/v2
Minimalist self-hosted RSS feed reader with PostgreSQL backend
awesome-incident-response
meirwah/awesome-incident-response
Incident response tools and DFIR resources for security operations teams
tpotce
telekom-security/tpotce
All-in-one multi honeypot platform for deception and threat detection
external-dns
kubernetes-sigs/external-dns
Kubernetes controller for automatically managing DNS records from ingress resources
autoscaler
kubernetes/autoscaler
Kubernetes autoscaling components for dynamic resource management
falco
falcosecurity/falco
Cloud-native runtime security monitoring with eBPF and container support
gosec
securego/gosec
Static analysis security scanner specifically designed for Go applications
star-history
star-history/star-history
Visualize GitHub star growth history — great for evaluating project momentum
Virtual-Display-Driver
VirtualDrivers/Virtual-Display-Driver
Virtual display driver for Windows - useful for VR, streaming, and remote desktop setups
git-credential-manager
git-ecosystem/git-credential-manager
Cross-platform Git credential manager with secure auth for major Git services
buildah
containers/buildah
Tool for building OCI container images without Docker daemon - rootless builds
trape
jofpin/trape
Internet people tracker combining OSINT analysis with social engineering
osv-scanner
google/osv-scanner
OSV.dev vulnerability scanner for finding security issues in dependencies
checkov
bridgecrewio/checkov
Multi-cloud misconfiguration scanner for IaC, containers, and packages
anteon
getanteon/anteon
eBPF-based Kubernetes monitoring and performance testing platform
syft
anchore/syft
Generate Software Bill of Materials (SBOM) from container images and filesystems
alertmanager
prometheus/alertmanager
Alert management for Prometheus - handles deduplication and routing to notification channels
GRDB.swift
groue/GRDB.swift
Swift SQLite toolkit with focus on application development and database observation
GhostTrack
HunxByts/GhostTrack
Mobile number and location tracking tool for OSINT gathering
simplewall
henrypp/simplewall
Simple Windows firewall configuration tool for network activity control
imaginAIry
brycedrennan/imaginAIry
Pythonic AI tool for generating images and videos with AI models
NETworkManager
BornToBeRoot/NETworkManager
Network management GUI tool with port scanning, monitoring, and troubleshooting
PrivateBin
PrivateBin/PrivateBin
Zero-knowledge encrypted pastebin for secure data sharing with client-side encryption
kube-bench
aquasecurity/kube-bench
CIS Kubernetes benchmark compliance checker for security best practices
flux2
fluxcd/flux2
GitOps continuous delivery platform for Kubernetes with Helm and Kustomize support
MONAI
Project-MONAI/MONAI
Healthcare imaging AI toolkit from Project MONAI for medical image processing
bandit
PyCQA/bandit
Static analysis tool for finding common security issues in Python code
hackrf
greatscottgadgets/hackrf
Software-defined radio platform for RF security research and wireless testing
steampipe
turbot/steampipe
SQL-based cloud security posture management and compliance tool
tubearchivist
tubearchivist/tubearchivist
Self-hosted YouTube media server for content archiving and management
osint_stuff_tool_collection
cipher387/osint_stuff_tool_collection
Curated collection of hundreds of online OSINT tools
kata-containers
kata-containers/kata-containers
Lightweight VMs that provide container-like performance with VM security isolation
ntopng
ntop/ntopng
Web-based network traffic monitoring and analysis with real-time visibility
feroxbuster
epi052/feroxbuster
Fast Rust-based recursive web content discovery and URL bruteforcer
PoC-in-GitHub
nomi-sec/PoC-in-GitHub
Automated collection of proof-of-concept exploits and CVE research from GitHub
Wallos
ellite/Wallos
Self-hosted subscription tracking and budget management application
ScoutSuite
nccgroup/ScoutSuite
Multi-cloud security auditing tool for AWS, Azure, and GCP environments
kyverno
kyverno/kyverno
Policy-as-code engine for Kubernetes security and compliance management
cai
aliasrobotics/cai
AI Security framework for cybersecurity applications and LLM pentesting
DependencyCheck
dependency-check/DependencyCheck
OWASP dependency checker for finding vulnerabilities in application dependencies
awesome-home-assistant
frenck/awesome-home-assistant
Curated Home Assistant resources for IoT and smart home development
podman-desktop
podman-desktop/podman-desktop
Desktop GUI for managing containers and Kubernetes - developer-friendly Docker alternative
AutoResearchClaw
aiming-lab/AutoResearchClaw
Autonomous research agent generating complete papers from ideas with self-evolution
windhawk
ramensoftware/windhawk
Windows program customization marketplace and modding platform
reconftw
six2dez/reconftw
Automated reconnaissance tool that runs multiple security scanners on target domains
Winhance
memstechtips/Winhance
Windows system optimization and debloat tool for improving performance and privacy
calico
projectcalico/calico
Cloud-native networking and network security solution with identity-aware policies
homarr
ajnart/homarr
Customizable homeserver dashboard for managing Docker containers and services
aircrack-ng
aircrack-ng/aircrack-ng
Complete WiFi security auditing suite for wireless network penetration testing
tfsec
aquasecurity/tfsec
Terraform security scanner now integrated into Trivy for IaC analysis
mac-dev-playbook
geerlingguy/mac-dev-playbook
Ansible playbook for automated Mac developer environment setup
al-khaser
ayoubfaouzi/al-khaser
Collection of anti-analysis techniques used by malware in the wild
awesome-appsec
paragonie/awesome-appsec
Curated collection of application security learning resources and references
RsaCtfTool
RsaCtfTool/RsaCtfTool
RSA attack tool for CTF challenges and cryptographic exploitation
caldera
mitre/caldera
MITRE's automated adversary emulation platform for red team operations
awesome-web-hacking
infoslack/awesome-web-hacking
Curated list of web application security resources and hacking tools
DevSecOps
sottlmarek/DevSecOps
Ultimate DevSecOps resource library and tool collection
spicedb
authzed/spicedb
Zanzibar-inspired authorization database for fine-grained access control
app
simple-login/app
Privacy-focused email aliasing service to protect email addresses
lolcat
busyloop/lolcat
Ruby CLI tool that adds rainbow colors to terminal output - fun terminal utility
external-secrets
external-secrets/external-secrets
Kubernetes operator that syncs secrets from external providers like AWS Secrets Manager
WhatWeb
urbanadventurer/WhatWeb
Web application fingerprinting scanner for identifying technologies and versions
linux-exploit-suggester
The-Z-Labs/linux-exploit-suggester
Linux privilege escalation auditing tool that suggests applicable kernel exploits
Responder
lgandx/Responder
LLMNR/NBT-NS poisoner with rogue authentication server for credential harvesting
cloudquery
cloudquery/cloudquery
Cloud asset inventory and CSPM data pipeline for security posture
awesome-tf
shuaibiyy/awesome-tf
Terraform and OpenTofu resources for infrastructure as code
k3d
k3d-io/k3d
Helper tool to run k3s Kubernetes clusters in Docker containers
faraday
infobyte/faraday
Open source vulnerability management platform with tool integration and reporting
Big-Ass-Data-Broker-Opt-Out-List
yaelwrites/Big-Ass-Data-Broker-Opt-Out-List
Comprehensive list for opting out of data broker services to protect privacy
Prowlarr
Prowlarr/Prowlarr
Indexer manager/proxy for torrent trackers and Usenet integration
x11docker
mviereck/x11docker
Security-focused tool to run GUI applications in isolated Docker containers
awesome-security-hardening
decalage2/awesome-security-hardening
Curated collection of security hardening guides and best practices
MISP
MISP/MISP
Open source threat intelligence platform for sharing IOCs and malware analysis
thelounge
thelounge/thelounge
Modern self-hosted web IRC client for team communication
osmedeus
j3ssie/osmedeus
Modern orchestration engine combining AI workflows for security testing
Arjun
s0md3v/Arjun
HTTP parameter discovery suite for API fuzzing and web application testing
kubernetes-network-policy-recipes
ahmetb/kubernetes-network-policy-recipes
Ready-to-use Kubernetes Network Policy examples for microsegmentation
actions-runner-controller
actions/actions-runner-controller
Kubernetes controller for managing GitHub Actions self-hosted runners at scale
playwright-cli
microsoft/playwright-cli
Microsoft's CLI for Playwright browser automation, code generation and debugging
xxh
xxh/xxh
Portable shell environment over SSH with support for multiple shell types
openvscode-server
gitpod-io/openvscode-server
Remote VS Code server accessible through web browser from any device
blackbird
p1ngul1n0/blackbird
Social media account discovery by username and email
awesome-bugbounty-tools
vavkamil/awesome-bugbounty-tools
Bug bounty tools collection for web security testing
permify
Permify/permify
Google Zanzibar-inspired authorization service for fine-grained permissions
cupp
Mebus/cupp
Generates custom wordlists based on user profiling for password attacks
naabu
projectdiscovery/naabu
Fast Go-based port scanner for attack surface discovery in pentests
k0s
k0sproject/k0s
Zero friction Kubernetes distribution for simplified cluster deployment
Cosmos-Server
azukaar/Cosmos-Server
Secure self-hosted server platform with built-in authentication and DDoS protection
mosint
alpkeskin/mosint
Automated email OSINT tool with data breach hunting capabilities
DesktopCommanderMCP
wonderwhy-er/DesktopCommanderMCP
MCP server giving Claude terminal control and file system capabilities
cosign
sigstore/cosign
Keyless code signing and verification for containers and software artifacts
Organizr
causefx/Organizr
Homelab services dashboard organizer with service management interface
commix
commixproject/commix
Automated OS command injection detection and exploitation tool
webmin
webmin/webmin
Web-based server management control panel for system administration
guide
hobby-kube/guide
Cost-effective Kubernetes cluster setup guide for hobbyists and small-scale
can-i-take-over-xyz
EdOverflow/can-i-take-over-xyz
Comprehensive list of services vulnerable to subdomain takeover attacks
kubernetes-goat
madhuakula/kubernetes-goat
Vulnerable by design Kubernetes cluster for hands-on security training
Top10
OWASP/Top10
Official OWASP Top 10 security risks documentation for web applications
cinnamon
linuxmint/cinnamon
Linux desktop environment with traditional layout and modern features
dangerzone
freedomofpress/dangerzone
Converts potentially dangerous documents to safe PDFs for malware mitigation
ansible-collection-hardening
dev-sec/ansible-collection-hardening
Ansible collection for hardening Linux, SSH, nginx, and MySQL systems
awesome-uses
wesbos/awesome-uses
Curated list of developer setups and configurations for workspace optimization
awesome-cybersecurity-blueteam
fabacab/awesome-cybersecurity-blueteam
Comprehensive blue team cybersecurity resources and defensive security tools
libreddit
libreddit/libreddit
Privacy-focused Reddit frontend for secure browsing
raspap-webgui
RaspAP/raspap-webgui
Full-featured wireless router web interface for Raspberry Pi and Debian devices
Empire
BC-SECURITY/Empire
Post-exploitation PowerShell framework for red team and penetration testing
microsandbox
zerocore-ai/microsandbox
Secure local-first sandboxes for AI agents with cross-platform support
kube-hunter
aquasecurity/kube-hunter
Kubernetes cluster security weakness scanner and penetration testing tool
hakrawler
hakluke/hakrawler
Fast web crawler for discovering endpoints and assets in web applications
mimir
grafana/mimir
Scalable long-term storage backend for Prometheus metrics and observability data
mayhem-firmware
portapack-mayhem/mayhem-firmware
Portable SDR firmware for HackRF enabling mobile RF testing and analysis
h8mail
khast3x/h8mail
Email breach hunting with premium service integration support
dalfox
hahwul/dalfox
Powerful automated XSS scanner with CI/CD integration for security testing
shlink
shlinkio/shlink
Self-hosted URL shortener with REST API for link management
pouch
AliyunContainerService/pouch
Enterprise container engine focused on efficiency, isolation, and security
CDK
cdk-team/CDK
Kubernetes, Docker, and Containerd security testing toolkit with container escapes
WebHackersWeapons
hahwul/WebHackersWeapons
Curated collection of web hacking tools and resources for bug bounty
awesome-threat-detection
0x4D31/awesome-threat-detection
Curated list of threat detection and hunting resources for security analysts
robin
apurvsinghgautam/robin
AI-powered dark web investigation and OSINT tool
IntelOwl
intelowlproject/IntelOwl
Scalable threat intelligence platform for IOC enrichment and malware analysis
diun
crazy-max/diun
Docker registry monitoring tool for automated update notifications
JimsGarage
JamesTurland/JimsGarage
Collection of homelab configuration files and scripts for self-hosting enthusiasts
kvm
jetkvm/kvm
Remote KVM solution for controlling computers over network connections
awesome-termux-hacking
may215/awesome-termux-hacking
Curated list of Termux-based hacking and OSINT tools
notion-py
jamalex/notion-py
Python API client for Notion workspace automation and integration
Mythic
its-a-feature/Mythic
Multi-platform collaborative red teaming framework for advanced operations
caddy-docker-proxy
lucaslorentz/caddy-docker-proxy
Caddy web server configured as reverse proxy for Docker containers
awesome-newsletters
zudochkin/awesome-newsletters
Tech newsletters for staying updated on industry developments
LinkFinder
GerbenJavado/LinkFinder
JavaScript endpoint discovery tool for web application reconnaissance
unifios-utilities
unifi-utilities/unifios-utilities
UniFi Dream Machine utilities for enhanced network management and security tools
interactsh
projectdiscovery/interactsh
Out-of-band interaction server for detecting blind vulnerabilities
Harden-Windows-Security
HotCakeX/Harden-Windows-Security
Comprehensive Windows security hardening toolkit with official Microsoft methods
agent-os
buildermethods/agent-os
System for injecting codebase standards and improving spec-driven development
retire.js
RetireJS/retire.js
Scanner for JavaScript libraries with known vulnerabilities and SBOM generation
docker-webtop
linuxserver/docker-webtop
Containerized Linux desktop environments accessible through web browsers
Tdarr
HaveAGitGat/Tdarr
Distributed video/audio transcoding automation with health checking
awesome-devops
wmariuss/awesome-devops
Curated DevOps tools, platforms, and best practices resource collection
volatility3
volatilityfoundation/volatility3
Advanced memory forensics framework for analyzing RAM dumps and malware
ivre
ivre/ivre
Self-hosted network recon framework - alternative to Shodan/ZoomEye with Nmap/Masscan
warehouse
pypi/warehouse
Official Python Package Index (PyPI) warehouse implementation
nextdns
nextdns/nextdns
NextDNS CLI client providing DNS-over-HTTPS proxy functionality
privacyguides.org
privacyguides/privacyguides.org
Privacy and security guidance resource for protection against surveillance
TorBot
DedSecInside/TorBot
Dark web crawler and OSINT tool for Tor network investigation
nut
networkupstools/nut
Network UPS management tools for monitoring and controlling power systems
linux-smart-enumeration
diego-treitos/linux-smart-enumeration
Linux enumeration tool for pentesting and CTF privilege escalation
reverse-shell-generator
0dayCTF/reverse-shell-generator
Web-based reverse shell generator with multiple payload types for pentesting and CTFs
IMSI-catcher
Oros42/IMSI-catcher
Tool for capturing IMSI numbers from nearby cellular devices using SDR hardware
chartmuseum
helm/chartmuseum
Helm chart repository server for managing Kubernetes application packages
toutatis
megadose/toutatis
Instagram account information extraction tool for OSINT
securedrop
freedomofpress/securedrop
Secure whistleblower platform for anonymous document submission
OSCE3-Complete-Guide
JoasASantos/OSCE3-Complete-Guide
Complete study guide for OSCE3 certification tracks (OSWE, OSEP, OSED, OSEE)
yarr
nkanaev/yarr
Lightweight self-hosted RSS reader for personal content management
PrivescCheck
itm4n/PrivescCheck
PowerShell privilege escalation enumeration script specifically for Windows systems
sslyze
nabla-c0d3/sslyze
Fast SSL/TLS scanning library for security assessments and vulnerability testing
Fuzzing101
antonio-morales/Fuzzing101
Step-by-step fuzzing tutorial covering AFL, fuzzilli and other fuzzing techniques
feedbin
feedbin/feedbin
Web-based RSS reader platform for content aggregation and management
cloudsploit
aquasecurity/cloudsploit
Cloud Security Posture Management tool for multi-cloud environments
composerize
composerize/composerize
Converts docker run commands to docker-compose format for easier management
ansible-nas
davestephens/ansible-nas
Ansible playbook for building full-featured home server and NAS systems
Findomain
Findomain/Findomain
Fast subdomain discovery with port scanning and monitoring features
sdrangel
f4exb/sdrangel
Feature-rich SDR software for RF reception and transmission across multiple platforms
dependency-track
DependencyTrack/dependency-track
OWASP component analysis platform for software supply chain risk reduction
docker-swag
linuxserver/docker-swag
Nginx reverse proxy with Let's Encrypt and fail2ban intrusion prevention
Anthropic-Cybersecurity-Skills
mukul975/Anthropic-Cybersecurity-Skills
Structured cybersecurity skills dataset for AI agents mapped to MITRE ATT&CK
PyRIT
Azure/PyRIT
Risk identification framework for red teaming and testing generative AI systems
gqrx
gqrx-sdr/gqrx
GUI SDR receiver for RF signal analysis and monitoring
assetfinder
tomnomnom/assetfinder
Simple tool for finding domains and subdomains related to a target domain
Raccoon
evyatarmeged/Raccoon
High-performance reconnaissance and vulnerability scanning platform
cloudgoat
RhinoSecurityLabs/cloudgoat
Vulnerable AWS environment deployment tool for cloud security training
SSRFmap
swisskyrepo/SSRFmap
Automatic SSRF fuzzer and exploitation tool for pentesting
docker-volume-backup
offen/docker-volume-backup
Backup Docker volumes to S3, WebDAV, Azure, Dropbox, and other storage
OSINT
sinwindie/OSINT
Collection of OSINT tools and methodologies for intelligence gathering
dashdot
MauriceNino/dashdot
Modern server dashboard for monitoring system resources and services
coraza
corazawaf/coraza
OWASP web application firewall library compatible with ModSecurity
claude-code-hooks-mastery
disler/claude-code-hooks-mastery
Educational resource for mastering Claude Code Hooks functionality
Stowaway
ph4ntonn/Stowaway
Multi-hop proxy tool for red team operations and pentesting
craft-agents-oss
lukilabs/craft-agents-oss
Open-source AI agent crafting framework (minimal description available)
cariddi
edoardottt/cariddi
Domain crawler for endpoint discovery, secrets, and API key detection
timesketch
google/timesketch
Collaborative forensic timeline analysis platform for incident response
SecretScanner
deepfence/SecretScanner
Container secret scanner for passwords and API keys in images and filesystems
pypykatz
skelsec/pypykatz
Pure Python implementation of Mimikatz for credential extraction
metorial
metorial/metorial
AI model integration platform with 600+ services using Model Context Protocol
kubectl
kubernetes/kubectl
Command-line interface tool for managing Kubernetes clusters and resources
SimpleMem
aiming-lab/SimpleMem
Efficient lifelong memory system for LLM agents with compression and retrieval
dockle
goodwithtech/dockle
Docker image linter for security best practices and compliance checking
Mr.Holmes
Lucksi/Mr.Holmes
Comprehensive OSINT framework with multiple information gathering modules
cloud-nuke
gruntwork-io/cloud-nuke
Tool for cleaning up cloud resources by deleting all resources in accounts
httprobe
tomnomnom/httprobe
Probe domains for working HTTP/HTTPS servers during reconnaissance
ContainerSSH
ContainerSSH/ContainerSSH
On-demand container launcher over SSH for development and testing
OpenShell
NVIDIA/OpenShell
NVIDIA's secure runtime environment for autonomous AI agents with safety controls
APT_REPORT
blackorbird/APT_REPORT
Curated collection of APT reports and IOCs for threat hunting and analysis
ddns-updater
qdm12/ddns-updater
Containerized dynamic DNS updater with web UI for multiple providers
AttackSurfaceAnalyzer
microsoft/AttackSurfaceAnalyzer
Microsoft tool for analyzing OS security configuration changes during software installs
littlelink
sethcottle/littlelink
Lightweight self-hosted link aggregation tool, alternative to Linktree for developers
NextDNS-Config
yokoffing/NextDNS-Config
DNS-over-HTTPS proxy configuration guide with ad/malware blocking capabilities
Pentest-Cheat-Sheets
Kitsun3Sec/Pentest-Cheat-Sheets
Penetration testing command reference and code snippet collection
selfhosted-apps-docker
DoTheEvo/selfhosted-apps-docker
Guide for self-hosting applications with Docker examples
uncover
projectdiscovery/uncover
Multi-engine search tool for discovering exposed hosts across the internet
portainer-templates
Lissy93/portainer-templates
Curated collection of 500+ one-click Portainer application templates
awesome-game-security
gmh5225/awesome-game-security
Game security resources covering anti-cheat, reverse engineering, and protection
Snaffler
SnaffCon/Snaffler
File discovery tool for penetration testers to find sensitive data and credentials
wizarr
wizarrrr/wizarr
User invitation and management system for media servers like Plex/Jellyfin
home-ops
onedr0p/home-ops
Complete GitOps homelab setup with Kubernetes, Flux, and infrastructure automation
php-reverse-shell
pentestmonkey/php-reverse-shell
PHP reverse shell script for web application penetration testing
dnsx
projectdiscovery/dnsx
Fast DNS toolkit for enumeration and resolution with wildcard filtering
medicat_installer
mon5termatt/medicat_installer
Medicat installer for IT support and system recovery tools
yopass
jhaals/yopass
Secure one-time sharing of secrets and passwords with encryption
cluster-template
onedr0p/cluster-template
Complete Kubernetes cluster template with Talos, Flux GitOps, and security best practices
stego-toolkit
DominicBreuker/stego-toolkit
Collection of steganography tools for CTF challenges
IOSSecuritySuite
securing/IOSSecuritySuite
iOS anti-tampering and security detection library for mobile app protection
PacketSender
dannagle/PacketSender
Cross-platform network utility for sending/receiving TCP, UDP, SSL, HTTP packets
email2phonenumber
martinvigo/email2phonenumber
Phone number discovery through email address OSINT techniques
Elkeid
bytedance/Elkeid
ByteDance open-source CWPP/EDR for hosts, containers, K8s, and serverless
Awesome-Telegram-OSINT
ItIsMeCall911/Awesome-Telegram-OSINT
Curated resources for Telegram-focused OSINT investigations
gsd-2
gsd-build/gsd-2
Meta-prompting and context engineering system for long-running autonomous agents
hackingthe.cloud
Hacking-the-Cloud/hackingthe.cloud
Encyclopedia of offensive and defensive cloud security techniques and knowledge
pwnagotchi
jayofelony/pwnagotchi
Raspberry Pi WiFi penetration testing device using Bettercap
waymore
xnl-h4ck3r/waymore
Enhanced web archive data collection from Wayback Machine and other sources
Maestro
RunMaestro/Maestro
Command center for orchestrating and managing multiple AI agents
awesome-functional-python
sfermigier/awesome-functional-python
Functional programming resources and libraries for Python developers
godot-mcp
Coding-Solo/godot-mcp
MCP server for Godot integration, enables AI agents to control game engine workflows
pwnedOrNot
thewhiteh4t/pwnedOrNot
Email breach checking using HaveIBeenPwned API integration
nexfil
thewhiteh4t/nexfil
Fast username enumeration across multiple social platforms
BurpSuite-For-Pentester
Ignitetechnologies/BurpSuite-For-Pentester
Comprehensive BurpSuite cheatsheet for bug bounty hunters and pentesters
SUDO_KILLER
TH3xACE/SUDO_KILLER
Sudo privilege escalation exploitation tool for pentesting
PCredz
lgandx/PCredz
Extracts credentials and sensitive data from pcap files or live network interfaces
FBI-tools
danieldurnea/FBI-tools
Curated collection of OSINT and digital forensics tools
terraform-best-practices
antonbabenko/terraform-best-practices
Comprehensive Terraform best practices ebook translated into multiple languages
awesome-engineering-team-management
kdeldycke/awesome-engineering-team-management
Engineering management transition guide for developers moving to leadership roles
cloudflare-ddns
favonia/cloudflare-ddns
Feature-rich Cloudflare DDNS updater with Docker support
hacking-resources
Lifka/hacking-resources
Comprehensive hacking resources and cheat sheets for offensive/defensive security
awesome-cloud-native
rootsongjc/awesome-cloud-native
Curated cloud native tools and tutorials for modern infrastructure
traefik-forward-auth
thomseddon/traefik-forward-auth
OAuth-based forward authentication service for Traefik reverse proxy
cloudfox
BishopFox/cloudfox
Automated situational awareness tool for cloud penetration testing
one_gadget
david942j/one_gadget
Tool for finding one gadget RCE exploits in libc libraries
MetaClaw
aiming-lab/MetaClaw
Conversational agent that learns and evolves through continual learning and meta-learning
Awesome-OSINT-For-Everything
Astrosp/Awesome-OSINT-For-Everything
Curated collection of OSINT tools for information gathering and recon
RedTeam-OffensiveSecurity
bigb0sss/RedTeam-OffensiveSecurity
Collection of tools and resources for red team operations and offensive security
ansible-role-docker
geerlingguy/ansible-role-docker
Ansible role for automated Docker installation and configuration
borgmatic
borgmatic-collective/borgmatic
Configuration-driven backup automation for servers with deduplication and monitoring
unmanic
Unmanic/unmanic
Media library optimization tool for automated file conversion and management
cloudsplaining
salesforce/cloudsplaining
AWS IAM privilege escalation and least privilege violation assessment tool
AutomatedLab
AutomatedLab/AutomatedLab
PowerShell framework for automated Windows/Linux lab deployment on HyperV/Azure
awesome-iam
kdeldycke/awesome-iam
Comprehensive identity and access management knowledge base for cloud security
vscode
catppuccin/vscode
Soothing pastel theme for Visual Studio Code editor
snallygaster
hannob/snallygaster
Scanner for discovering secret files and sensitive information on web servers
f8x
ffffffff0x/f8x
Red/blue team environment automation deployment tool
CTFCrackTools
0Chencc/CTFCrackTools
Next-generation CTF Swiss Army Knife with visual workflow
smuggler
defparam/smuggler
HTTP request smuggling and desync testing tool for finding protocol vulnerabilities
agentic-context-engine
kayba-ai/agentic-context-engine
Context engine enabling agents to learn from experience with memory management
plaso
log2timeline/plaso
Timeline analysis tool for digital forensics investigations and incident response
smbmap
ShawnDEvans/smbmap
SMB enumeration tool for network reconnaissance and share discovery
hub
artifacthub/hub
Cloud Native package discovery and management platform for Kubernetes ecosystem
ToolsFx
Leon406/ToolsFx
Cross-platform crypto toolbox for CTF and cryptography challenges
FIR
certsocietegenerale/FIR
Fast incident response platform for security teams and forensic investigations
metasploit-payloads
rapid7/metasploit-payloads
Unified repository for Metasploit Framework payloads and exploits
FISSURE
ainfosec/FISSURE
Comprehensive RF and reverse engineering framework for wireless protocol analysis
ggshield
GitGuardian/ggshield
Advanced secrets detection with 500+ validators for CI/CD pipelines
owtf
owtf/owtf
Offensive Web Testing Framework for efficient penetration testing workflows
octosuite
bellingcat/octosuite
Terminal toolkit for analyzing GitHub data and conducting OSINT investigations
awesome-lockpicking
fabacab/awesome-lockpicking
Physical security resources covering lockpicking and lock bypass techniques
slsa
slsa-framework/slsa
Framework defining supply-chain security levels for software artifacts
resources
ctfs/resources
General collection of CTF information, tools, and tips
murphysec
murphysecurity/murphysec
Open source SCA tool for dependency vulnerability detection
Maintainerr
Maintainerr/Maintainerr
Library maintenance tool for Plex and Jellyfin media servers
launchpad
timothystewart6/launchpad
HomeLab automation collection with Docker, Kubernetes, and Ansible templates
hardening
konstruktoid/hardening
Ubuntu hardening scripts with systemd integration for security compliance
hping
antirez/hping
Network tool for packet crafting, firewall testing, and port scanning
ctftool
taviso/ctftool
Interactive CTF exploration tool for reverse engineering
awesome-soc
cyb3rxp/awesome-soc
Curated knowledge base for building and running Security Operations Centers
wordlists
assetnote/wordlists
Curated wordlists for content discovery and web application penetration testing
Starkiller
BC-SECURITY/Starkiller
Web-based GUI frontend for managing PowerShell Empire C2 operations
Name-That-Hash
bee-san/Name-That-Hash
Hash identification tool for CTF and security research
container-security-checklist
krol3/container-security-checklist
Comprehensive container security checklist for DevSecOps practices
gitjacker
liamg/gitjacker
Extracts git repositories from misconfigured websites to find exposed source code
copacetic
project-copacetic/copacetic
CLI tool for direct container image patching and vulnerability remediation
hakrevdns
hakluke/hakrevdns
Fast tool for performing bulk reverse DNS lookups during reconnaissance
nomore403
devploit/nomore403
Advanced HTTP 403 bypass tool for security researchers
enum4linux-ng
cddmp/enum4linux-ng
Next-gen Windows/Samba enumeration tool for CTF and pentesting
nanocoder
Nano-Collective/nanocoder
Local-first coding agent running in terminal with community focus
xnLinkFinder
xnl-h4ck3r/xnLinkFinder
Discovers endpoints, parameters, and secrets from web applications for recon
mcp-memory-service
doobidoo/mcp-memory-service
Persistent memory service for AI agents with knowledge graph and vector storage
GAP-Burp-Extension
xnl-h4ck3r/GAP-Burp-Extension
Burp extension for finding potential endpoints and generating custom wordlists
windows-privesc-check
pentestmonkey/windows-privesc-check
Windows privilege escalation checker identifying common attack vectors
docker-mods
linuxserver/docker-mods
Documentation and examples for modifying LinuxServer base containers
mutillidae
webpwnized/mutillidae
Deliberately vulnerable web application for security training
harbor-helm
goharbor/harbor-helm
Official Helm chart for deploying Harbor container registry on Kubernetes
nebula-sync
lovelaze/nebula-sync
Synchronization tool for managing multiple Pi-hole DNS instances across networks
secure-ios-app-dev
felixgr/secure-ios-app-dev
Collection of common iOS app vulnerabilities for security assessment reference
git-hound
tillson/git-hound
GitHub-wide secret scanning tool for credential leak detection
bypass-mdm
assafdori/bypass-mdm
Tool for bypassing macOS Mobile Device Management (MDM) setup restrictions
stash
stashed/stash
Kubernetes stateful application backup solution using Restic
hindsight
obsidianforensics/hindsight
Browser forensics tool for Chrome/Chromium analyzing browsing history and artifacts
webauthn
w3c/webauthn
W3C Web Authentication API specification for public key credential access
AIL-framework
CIRCL/AIL-framework
Analysis framework for information leaks and privacy security incidents
PeaNUT
Brandawg93/PeaNUT
Network UPS monitoring dashboard for infrastructure management
threat-dragon
OWASP/threat-dragon
OWASP threat modeling tool for identifying security risks in application design
Auto_Wordlists
carlospolop/Auto_Wordlists
Automated wordlist generation tool for security testing and brute force
HidHide
nefarius/HidHide
Windows input device firewall for controlling gaming peripheral access
TREVORspray
blacklanternsecurity/TREVORspray
Modular password spraying tool with threading and proxy support for Office 365
docker-pihole-unbound
mpgirro/docker-pihole-unbound
Docker setup for Pi-Hole DNS blocking with Unbound recursive DNS
CaptfEncoder
guyoung/CaptfEncoder
Cross-platform network security tool suite for CTF and crypto
stackrox
stackrox/stackrox
Kubernetes security platform with runtime monitoring and risk analysis
trivy-action
aquasecurity/trivy-action
GitHub Action for Trivy vulnerability scanning of Docker containers
Telos
danielmiessler/Telos
Framework for creating deep context about human-relevant topics
bane
genuinetools/bane
Custom AppArmor profile generator for enhanced Docker container security
SharpHound
SpecterOps/SharpHound
C# data collector for BloodHound Active Directory attack path analysis
dagda
eliasgranderubio/dagda
Docker image vulnerability scanner with malware detection and runtime monitoring
artifacts
ForensicArtifacts/artifacts
Comprehensive repository of digital forensics artifacts and definitions
Signal-TLS-Proxy
signalapp/Signal-TLS-Proxy
TLS proxy for Signal messaging service network security
qscan
qi4L/qscan
Lightning-fast internal network scanner for reconnaissance activities
Artemis
CERT-Polska/Artemis
Modular vulnerability scanner with automatic report generation capabilities
Hemmelig.app
HemmeligOrg/Hemmelig.app
Encrypted secret sharing platform for secure information exchange
OpenSCA-cli
XmirrorSecurity/OpenSCA-cli
Open source SCA with SBOM generation and license compliance checking
rekor
sigstore/rekor
Transparency log for software supply chain provenance and security verification
jok3r
koutto/jok3r
Network and web pentest automation framework with vulnerability exploitation
Beginners-Guide-to-Obfuscation
BC-SECURITY/Beginners-Guide-to-Obfuscation
Educational guide on obfuscation techniques for security professionals
gitsign
sigstore/gitsign
Keyless Git commit signing using Sigstore for secure software development
Aggressor
k8gege/Aggressor
Cobalt Strike extension with large network penetration scanning capabilities
Pi.Alert
leiweibau/Pi.Alert
Network device discovery and monitoring for detecting unauthorized connections
Silver
s0md3v/Silver
Mass IP scanner for identifying vulnerable services across networks
The-Hacker-Recipes
The-Hacker-Recipes/The-Hacker-Recipes
Comprehensive technical guides and documentation for cybersecurity practitioners
goscan
marco-lancini/goscan
Interactive network scanner built with Go for pentesting activities
mash-playbook
mother-of-all-self-hosting/mash-playbook
Comprehensive Ansible playbook for self-hosting multiple services
flipper-application-catalog
flipperdevices/flipper-application-catalog
Application catalog for Flipper Zero security research and penetration testing
plugins
serverless/plugins
Community plugins extending Serverless Framework functionality
hakoriginfinder
hakluke/hakoriginfinder
Discovers origin hosts behind reverse proxies to bypass cloud WAFs
in-toto
in-toto/in-toto
Framework for protecting software supply chain integrity with attestations
StreamController
StreamController/StreamController
Elegant Linux app for Stream Deck with plugin support
SoftRF
lyusupov/SoftRF
Multi-platform aviation proximity awareness system for DIY aircraft tracking
volsync
backube/volsync
Kubernetes operator for asynchronous data replication and disaster recovery
skanuvaty
Esc4iCEscEsc/skanuvaty
High-performance DNS/network/port scanner with subdomain enumeration capabilities
zap-extensions
zaproxy/zap-extensions
ZAP add-ons collection for the popular web application security scanner
Flipper-iOS-App
flipperdevices/Flipper-iOS-App
iOS app for managing Flipper Zero hardware security testing device
BTLE
JiaoXianjun/BTLE
BLE packet sniffer/transmitter for wireless security testing and protocol analysis
Linux-Privilege-Escalation
Ignitetechnologies/Linux-Privilege-Escalation
Linux privilege escalation cheatsheet for OSCP and CTF preparation
skipfish
spinkham/skipfish
Web application security scanner by lcamtuf for finding vulnerabilities
log4j2burpscanner
f0ng/log4j2burpscanner
BurpSuite extension for detecting CVE-2021-44228 Log4j2 vulnerabilities
gattacker
securing/gattacker
Bluetooth Low Energy security testing tool with MITM attack capabilities
fulcio
sigstore/fulcio
OIDC-based PKI certificate authority for keyless code signing infrastructure
goscan
timest/goscan
Efficient IPv4 network scanner for discovering active devices on LANs
cargo-vet
mozilla/cargo-vet
Mozilla's supply-chain security auditing tool for Rust dependencies
tlosint-live
tracelabs/tlosint-live
OSINT-focused Linux distribution based on Kali for open source intelligence gathering
chain-bench
aquasecurity/chain-bench
CIS-based compliance auditing for software supply chain security
Substrate
danielmiessler/Substrate
Framework for creating deep contextual understanding using AI
npm-security-best-practices
bodadotsh/npm-security-best-practices
Best practices guide for NPM supply chain attack prevention
rtl-sdr-scanner-cpp
shajen/rtl-sdr-scanner-cpp
SDR scanner for RF reconnaissance and signal analysis
hacktricks-cloud
HackTricks-wiki/hacktricks-cloud
Cloud-focused security knowledge base and penetration testing guide
crowdsec-bouncer-traefik-plugin
maxlerebourg/crowdsec-bouncer-traefik-plugin
Traefik plugin integrating CrowdSec for WAF and IP protection
dnsvalidator
vortexau/dnsvalidator
Maintains and validates list of reliable IPv4 DNS servers for reconnaissance
PurplePanda
carlospolop/PurplePanda
Multi-cloud privilege escalation path discovery tool for GCP, GitHub, Kubernetes
go-tuf
theupdateframework/go-tuf
Go implementation of The Update Framework for secure software updates
goaccess-for-nginxproxymanager
xavier-hernandez/goaccess-for-nginxproxymanager
GoAccess analytics Docker image specifically for Nginx Proxy Manager logs
packj
ossillate-inc/packj
Malicious dependency detection for preventing supply chain attacks
thgtoa
Anon-Planet/thgtoa
Comprehensive guide for online anonymity, OpSec, and privacy practices
images
chainguard-images/images
Distroless container images with minimal attack surface and security hardening
shell-plugins
1Password/shell-plugins
Shell plugins providing seamless authentication for terminal tools via 1Password
DreamDojo
NVIDIA/DreamDojo
NVIDIA's robot world model from large-scale human video data for generalist robotics
pyhtools
dmdhrumilmistry/pyhtools
Comprehensive Python hacking library with network and malware tools
Pulsarr
jamcalli/Pulsarr
Real-time Plex watchlist monitoring with automated media library management
samytools
samyk/samytools
Simple tools for reverse engineering and data manipulation on *nix systems
misp-galaxy
MISP/misp-galaxy
MISP threat actor clusters and attack patterns for structured threat intelligence
thiss.link
NayamAmarshe/thiss.link
Privacy-focused encrypted link shortener with password protection and self-hosting
HellRaiser
m0nad/HellRaiser
Nmap-based vulnerability scanner correlating CPEs with CVE database
evilscan
eviltik/evilscan
Simple NodeJS network scanner for port scanning and reconnaissance
chainloop
chainloop-dev/chainloop
SDLC evidence store with SBOM management and supply chain attestations
CloudScraper
jordanpotti/CloudScraper
Cloud storage enumeration tool for S3 buckets, Azure blobs, and DigitalOcean
pentmenu
GinjaChris/pentmenu
Bash script for network reconnaissance and DoS attacks
validation-benchmarks
xbow-engineering/validation-benchmarks
AI security validation benchmarks for testing AI model safety and security
witness
in-toto/witness
Pluggable framework for software artifact provenance verification
toolkit
bellingcat/toolkit
OSINT toolkit from Bellingcat for open source intelligence investigations
MMLanScan
mavris/MMLanScan
iOS library for LAN network scanning and device discovery
xmap
idealeer/xmap
Fast IPv4/IPv6 network scanner for Internet-wide research scanning
webscan
samyk/webscan
Browser-based network scanner with local IP detection capabilities
traefik-kop
jittering/traefik-kop
Dynamic service discovery agent for Docker containers with Traefik and Redis
docker-kasm
linuxserver/docker-kasm
Containerized Kasm Workspaces for browser-based virtual desktop environments
PowerShell_IPv4NetworkScanner
BornToBeRoot/PowerShell_IPv4NetworkScanner
Asynchronous IPv4 network scanner written in PowerShell
nautical-backup
Minituff/nautical-backup
Simple Docker volume backup tool for automated data protection
imgcrypt
containerd/imgcrypt
OCI container image encryption package for securing container workloads
hakcheckurl
hakluke/hakcheckurl
Go tool that takes URLs and returns HTTP response codes for web enumeration
streamdeck-linux-gui
streamdeck-linux-gui/streamdeck-linux-gui
Linux UI for Elgato Stream Deck hardware control
kubelet
kubernetes/kubelet
Kubelet component configurations for Kubernetes node management
ansible_homelab
rishavnandi/ansible_homelab
Ansible playbooks for automated homelab setup with Docker deployment
minder
mindersec/minder
Comprehensive software supply chain security management platform
misp-modules
MISP/misp-modules
MISP expansion modules for threat intelligence enrichment and data import/export
awesome-software-supply-chain-security
bureado/awesome-software-supply-chain-security
Comprehensive resource compilation for supply chain security
wiki
forensicswiki/wiki
Community wiki dedicated to digital forensics knowledge and techniques
sigstore-python
sigstore/sigstore-python
Python client for Sigstore software supply chain security and code signing
malicious-software-packages-dataset
DataDog/malicious-software-packages-dataset
Human-vetted dataset of malicious software packages for supply chain security research
dfiq
google/dfiq
Collection of investigative questions and approaches for digital forensics
dns
qdm12/dns
Secure DNS server with DNS-over-TLS support from multiple privacy providers
source-controller
fluxcd/source-controller
GitOps toolkit for managing source code repositories in Kubernetes deployments
chains
tektoncd/chains
Supply chain security integration for Tekton CI/CD pipelines
community.docker
ansible-collections/community.docker
Ansible collection for Docker container management and orchestration
op-vscode
1Password/op-vscode
1Password integration for VS Code enabling secure credential management
UBUNTU22-CIS
ansible-lockdown/UBUNTU22-CIS
Automated CIS benchmark compliance remediation for Ubuntu 22 using Ansible
sbomnix
tiiuae/sbomnix
Nix-focused SBOM generation and supply chain security utilities
back-me-up
Dheerajmadhukar/back-me-up
Scans wayback data for sensitive data leaks using regex patterns
SIGpi
joecupano/SIGpi
SIGINT toolkit for radio frequency analysis and amateur radio operations
model-transparency
sigstore/model-transparency
Machine learning model supply chain security with Sigstore integration
connect-sdk-python
1Password/connect-sdk-python
Python SDK for 1Password Connect API for programmatic secrets management
h1-brain
PatrikFehrenbach/h1-brain
MCP server connecting AI assistants to HackerOne for automated bug bounty hunting
connect
1Password/connect
1Password Connect server for programmatic access to 1Password secrets in automation
npmGrafStats
smilebasti/npmGrafStats
Exports Nginx Proxy Manager logs to InfluxDB for Grafana visualization
watchtower
bosch-aisecurity-aishield/watchtower
AI model vulnerability scanner for ML supply chain security
magpie
openraven/magpie
CSPM focused on cloud ransomware and supply chain attack analysis
macaron
oracle/macaron
Oracle's extensible supply-chain security analysis framework supporting multiple build systems
3os.org
fire1ce/3os.org
Technical documentation hub for DevOps, pentesting, and IT professionals
UBUNTU20-CIS
ansible-lockdown/UBUNTU20-CIS
Automated CIS benchmark compliance remediation for Ubuntu 20 using Ansible
secure-repository-supply-chain
skills/secure-repository-supply-chain
GitHub Skills course on securing supply chain and managing dependencies
docker-ddclient
linuxserver/docker-ddclient
Docker container for dynamic DNS client management
Daemon
danielmiessler/Daemon
Open-source personal API framework for custom integrations
Widgets-for-UniGetUI
Devolutions/Widgets-for-UniGetUI
Windows widgets for package manager UI, extends system package management capabilities
i-probably-didnt-backdoor-this
kpcyrd/i-probably-didnt-backdoor-this
Practical experiment on supply-chain security using reproducible builds
preflight
SpectralOps/preflight
Tool to verify scripts and executables against supply chain attacks
awesome-cloud-sec
RyanJarv/awesome-cloud-sec
Curated collection of cloud security tools and resources
terraform-provider-harbor
goharbor/terraform-provider-harbor
Terraform provider for Harbor container registry infrastructure as code
in-toto-golang
in-toto/in-toto-golang
Go implementation of in-toto framework for software supply chain integrity
Software-Supply-Chain-Security
vishalgarg-sec/Software-Supply-Chain-Security
Comprehensive compilation of Software Supply Chain Security resources and tools
agentseal
AgentSeal/agentseal
Security toolkit for AI agents - scan, monitor, test prompt injection, audit MCP servers
python-for-coding-interviews
mmicu/python-for-coding-interviews
Python algorithms and data structures reference for coding interviews
maloss
osssanitizer/maloss
Research tool for measuring supply chain attacks on package managers
docker-netbox
linuxserver/docker-netbox
Dockerized NetBox deployment for infrastructure management
image-reflector-controller
fluxcd/image-reflector-controller
GitOps component that scans container registries for image updates and vulnerabilities
subdover
PushpenderIndia/subdover
Multithreaded subdomain takeover vulnerability scanner with extensive fingerprints
pupy
AlessandroZ/pupy
Cross-platform RAT with in-memory execution and low footprint capabilities
cloudjack
prevade/cloudjack
AWS Route53/CloudFront vulnerability assessment and exploitation tool
BrewUp
fire1ce/BrewUp
Automated Homebrew package management and backup for macOS developers
safe-harbour
trickest/safe-harbour
Collection of security.txt files from popular domains for responsible disclosure
DeadDNS
DreyAnd/DeadDNS
Automated DNS hijacking tool for identifying vulnerable dead DNS records
Foremost
gerryamurphy/Foremost
File recovery tool using headers/footers analysis for digital forensics investigations
ansible-cis-ubuntu-2204
MVladislav/ansible-cis-ubuntu-2204
Ansible role for automated CIS Ubuntu 22.04 compliance and hardening
Eraserr
everettsouthwick/Eraserr
Media server maintenance automation for cleaning up unwatched content
SilverBullet-1.4.1-Pro-
v3nom-1337/SilverBullet-1.4.1-Pro-
Multi-proxy account checker tool for credential validation testing
yk-csr-generator
SheepReaper/yk-csr-generator
CLI tool for generating Certificate Signing Requests using YubiKey hardware tokens
CIPHER
defconxt/CIPHER
Claude-integrated security engineering assistant for privacy and hardening
BrewUp
defconxt/BrewUp
Homebrew package manager interface for macOS development environment management