| 10/08 | 9 |
Weighs the soul of connections using proof-of-work to protect resources from scraper bots.
|
| 10/06 | 9 |
Powerful tool for discovering, classifying, validating, and analyzing leaked credentials.
|
| 10/05 | 9 |
Community curated templates for the nuclei engine to identify security vulnerabilities in applications.
|
| 10/02 | 9 |
On-demand website intelligence dashboard that gathers network, security, and performance data to help analyze attack vectors and understand site technologies.
|
| 09/30 | 9 |
Static analysis tool checking Ruby on Rails applications for security vulnerabilities.
|
| 09/28 | 9 |
Manage dotfiles across multiple diverse machines securely.
|
| 09/17 | 9 |
Let's Encrypt client and ACME library written in Go.
|
| 09/16 | 9 |
Modern automation platform for security and IT engineers with YAML templates, no-code workflows, lookup tables, and case management.
|
| 10/09 | 8 |
Cloud-native policy-as-code engine that scans infrastructure, containers, Kubernetes, cloud services, and code for vulnerabilities and misconfigurations.
|
| 10/09 | 8 |
Cloud-native graph-based query language for querying and discovering infrastructure assets across clouds, containers, and services.
|
| 10/09 | 8 |
Edge virtualization engine providing hardware-assisted virtualization and resource partitioning for on-premises edge devices.
|
| 10/08 | 8 |
AI-powered security platform that scans codebases for secrets, vulnerabilities, CVEs, and generates prioritized remediation plans.
|
| 10/08 | 8 |
Local read-only multi-chain meme candidate scanner with GMGN-backed HTTP API access and manual review workflow.
|
| 10/07 | 8 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 10/07 | 8 |
Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support.
|
| 10/06 | 8 |
High-performance authorization engine for modeling and enforcing fine-grained access control inspired by Google Zanzibar.
|
| 10/06 | 8 |
Secret management platform for syncing secrets and configurations across teams and infrastructure while preventing leaks.
|
| 10/05 | 8 |
Kubernetes-native toolkit that continuously scans clusters and generates vulnerability, configuration, secrets, RBAC, compliance, and SBOM reports.
|
| 10/02 | 8 |
Vulnerability scanner for container images and filesystems.
|
| 10/01 | 8 |
Comprehensive security scanner for vulnerabilities, misconfigurations, and secrets across various targets.
|
| 09/30 | 8 |
Context-aware, YAML-defined access control with APIs for dynamic authorization decisions.
|
| 09/29 | 8 |
Enterprise-ready SIEM and XDR platform offering real-time log correlation, threat intelligence, and incident response.
|
| 09/28 | 8 |
General-purpose security automation platform for security teams, offering workflow editor, OpenAPI-based app creation, and resource sharing.
|
| 09/25 | 8 |
Easy-to-use CLI for building, operating, and automating PKI systems and common X.509, JWT, and crypto workflows.
|
| 09/24 | 8 |
Platform for engineering teams to secure, manage, and deploy application secrets across environments.
|
| 09/24 | 8 |
Out-of-band interaction gathering server and client library.
|
| 09/23 | 8 |
Software to manage, store, and distribute sensitive data like secrets, certificates, and keys.
|
| 09/22 | 8 |
Self-hosted web application firewall and reverse proxy that protects web apps from various attacks.
|
| 09/21 | 8 |
Collaboration framework designed for InfoSec teams.
|
| 09/21 | 8 |
Securely share sensitive information with automatic expiration and deletion after a set number of views or duration.
|
| 09/17 | 8 |
InSpec compliance profile enforcing consistent hardening checks across Linux systems.
|
| 09/15 | 8 |
Kubernetes-based modular toolchain for continuous security scanning of software projects.
|
| 09/14 | 8 |
Multi-cloud compliance scanner that audits AWS, Azure, GCP, and M365 against standards and generates audit-ready reports.
|
| 09/14 | 8 |
A Go-based website screenshot utility that uses Chrome Headless to capture web pages from the command line with optional reporting and saved results.
|
| 09/13 | 8 |
Tunnels internet traffic through VK Call and Yandex Telemost video platforms to bypass government whitelist censorship.
|
| 10/11 | 7 |
Fast, efficient osquery management server implementing the osquery remote API as a TLS endpoint.
|
| 10/10 | 7 |
Embeddable Go library or standalone auth server with plugin-based, composable authentication and extensible hooks.
|
| 10/08 | 7 |
CI/CD compliance scanner for GitLab pipelines
|
| 10/08 | 7 |
Canonical JavaScript/TypeScript SDK for the Socket.dev API, providing package scoring, quota management, batch lookups, and dependency analysis with built-in request handling.
|
| 10/08 | 7 |
Rails-oriented HotCell sidecar isolates untrusted computation in an unprivileged container with strict resource limits and file-descriptor based RPC.
|
| 10/08 | 7 |
Platform for managing, structuring, visualizing, and sharing cyber threat intelligence using a STIX2-based knowledge schema.
|
| 10/07 | 7 |
API for checking port availability on specified hostnames or IP addresses to assist network troubleshooting and firewall validation.
|
| 10/06 | 7 |
Middleware for limiting repeated requests to public APIs and endpoints.
|
| 10/03 | 7 |
Desktop proxy enabling scalable tool discovery, major token savings, and quarantine of malicious upstream servers for AI agents.
|
| 10/01 | 7 |
Kontext places local policy between AI agents and the tools they call, evaluating, enforcing, and recording authorization decisions before consequential actions run.
|
| 09/29 | 7 |
Proxy that secures and simplifies access to infrastructure with outbound-only connections and integrated SSO.
|
| 09/29 | 7 |
Comprehensive security platform for managing and securing Kubernetes environments throughout the development and deployment lifecycle.
|
| 09/28 | 7 |
Autonomous AI pentesting platform that runs an end-to-end methodology and uses independent re-exploitation to verify and prove vulnerabilities.
|
| 09/24 | 7 |
CLI tool that scans workflows and updates GitHub Actions, pinning them to exact commit SHAs.
|
| 09/23 | 7 |
Security auditing CLI for web applications supporting remote black-box scans and local white-box code audits.
|
| 09/23 | 7 |
Fast and tolerant XSS sanitizer for HTML, MathML, and SVG.
|
| 09/17 | 7 |
Counts and limits actions by key to protect against DDoS and brute force attacks.
|
| 09/16 | 7 |
A garbage-collected programming language focused on compile-time and runtime security via encrypted bytecode.
|
| 09/16 | 7 |
Zero-ETL tool for querying APIs and services using SQL.
|
| 09/15 | 7 |
Networking, observability, and security solution with an eBPF-based dataplane.
|
| 09/15 | 7 |
Browser extension for Firefox, Edge and Chrome providing secure cryptographic operations, random number generation, and password autofill.
JavaScript
277☆
3871d old
#javascript
#security
#productivity
#browser-extension
#password-manager
|
| 09/14 | 7 |
BeyondCorp-inspired HTTPS/SSO access proxy that controls access to internal services beyond your perimeter using OpenID Connect, OAuth2, or SAML.
|
| 09/12 | 7 |
Runtime access gateway enforcing identity-based egress policies and issuing ephemeral credentials so workloads have no long-lived secrets
|
| 09/11 | 7 |
Kubernetes operator that manages and scales SpiceDB clusters and automates datastore migrations.
|
| 09/11 | 7 |
Database for storing and querying fine-grained authorization data at scale.
|
| 09/11 | 7 |
Kubernetes/OpenShift operator that combines trusted certificate sources into a distributable trust bundle for applications.
|
| 09/11 | 7 |
Fabric-native secure WebView for React Native controlled web flows, validating navigations against an exact origin allowlist and emitting deep-link events instead of loading custom schemes.
|
| 10/10 | 6 |
JSON.parse() drop-in replacement that protects against prototype poisoning via __proto__ and constructor.prototype keys.
|
| 10/09 | 6 |
High-level Go packages providing APIs for interacting with TPM 2.0 devices.
|
| 10/06 | 6 |
End-to-end field-level encryption for TypeScript apps with zero-knowledge key management and searchable encrypted queries.
|
| 09/28 | 6 |
CLI that generates 8-hour GitHub App user access tokens via Device Flow for secure local development.
|
| 09/28 | 6 |
Zero-knowledge credential infrastructure that stores and injects credentials for AI agents without ever entering agent context, enabling enforcement, auditing, and redacted responses.
|
| 09/23 | 6 |
Collection of plugins that extend the Wazuh dashboard with UI panels for security events, integrity, vulnerability, and compliance monitoring.
|
| 09/22 | 6 |
Ruby gem providing git-managed LDAP group configuration and access provisioning for identity and access management.
|
| 09/19 | 6 |
FIDO2-conformant passkey and authentication backend for Go applications.
|
| 09/16 | 6 |
Visualize data sources and run compliance benchmarks for effective decision-making and ongoing monitoring.
|
| 09/15 | 6 |
Software supply chain security platform enforcing configurable policies, attesting artifacts, and managing repository security and dependency risk.
|
| 09/13 | 6 |
Go library exposing Linux Landlock sandboxing to restrict process file, network, and some IPC access.
|
| 10/07 | 5 |
Security-first personal AI assistant runtime providing multi-provider model access and multi-channel messaging integrations with local-first data control.
|
| 10/06 | 5 |
Windows-based, AI-powered all-in-one reverse engineering package manager for malware analysis, penetration testing, and education.
JavaScript
361☆
1285d old
#javascript
#security
#reverse-engineering
#penetration-testing
#awesome-list
|
| 10/04 | 5 |
JavaScript AST analysis tool for identifying potentially malicious code patterns.
|
| 09/30 | 5 |
Tool for database anonymization and synthetic data generation.
|
| 09/24 | 5 |
Autogenerated Go client wrapping a fine-grained authorization API for modeling and checking relationships.
|
| 09/23 | 5 |
Scans and monitors projects for security vulnerabilities in code, containers, dependencies, and infrastructure-as-code.
|
| 09/21 | 5 |
Extension that secures PostgreSQL in cloud environments by managing privileges without requiring superuser access.
|
| 09/16 | 5 |
Go-based distributed video surveillance system integrating third-party motion detectors for SBCs with server-client coordination, local processing, and event reporting.
|
| 09/15 | 5 |
Set of over 1500 AppArmor profiles to confine core Linux system services, desktop environments, and user processes.
|
| 09/14 | 5 |
Periodic Kubernetes API poller reporting containers, images, pods, nodes and namespaces currently in use.
|
| 09/12 | 5 |
Thunderbird user.js template providing privacy, security, and anti-fingerprinting settings while minimizing functionality loss in email-focused use.
|
| 09/25 | 4 |
Human-made Kubernetes security diagram cheatsheet that helps teams browse and discuss security concepts across Kubernetes components and controls.
|
| 09/24 | 4 |
Cybersecurity-focused domain-specific programming language with a dedicated virtual machine and IDE support.
|
| 09/17 | 4 |
Offline-first password manager that stores and encrypts vault data locally with optional TOTP and Google Drive synchronization.
|
| 10/06 | 3 |
Local-first EDR-style monitor tracking AI agent processes, file and network activity with per-agent risk scoring.
|
| 10/02 | 3 |
Best Practices Badge project that defines criteria and provides a BadgeApp web application for projects to self-certify compliance and display badges.
|
| 09/25 | 3 |
Offline-first password manager for macOS, Windows, and Linux with locally encrypted vault storage, strong password generation, TOTP support, and optional Google Drive sync.
|
| 10/10 | 2 |
A network security appliance firmware and companion mobile and web apps for managing and monitoring home or small office networks.
|
| 10/02 | 1 |
Continuous cloud-assurance platform that evaluates cloud configurations for security and compliance against standards like C5 and CSA CCM.
|