| 10/08 | 9 |
Weighs the soul of connections using proof-of-work to protect resources from scraper bots.
|
| 10/06 | 9 |
Powerful tool for discovering, classifying, validating, and analyzing leaked credentials.
|
| 10/05 | 9 |
Community curated templates for the nuclei engine to identify security vulnerabilities in applications.
|
| 10/09 | 8 |
Cloud-native policy-as-code engine that scans infrastructure, containers, Kubernetes, cloud services, and code for vulnerabilities and misconfigurations.
|
| 10/09 | 8 |
Cloud-native graph-based query language for querying and discovering infrastructure assets across clouds, containers, and services.
|
| 10/09 | 8 |
Modern automation platform for security and IT engineers with YAML templates, no-code workflows, lookup tables, and case management.
|
| 10/09 | 8 |
Edge virtualization engine providing hardware-assisted virtualization and resource partitioning for on-premises edge devices.
|
| 10/08 | 8 |
AI-powered security platform that scans codebases for secrets, vulnerabilities, CVEs, and generates prioritized remediation plans.
|
| 10/08 | 8 |
Local read-only multi-chain meme candidate scanner with GMGN-backed HTTP API access and manual review workflow.
|
| 10/07 | 8 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 10/07 | 8 |
Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support.
|
| 10/06 | 8 |
High-performance authorization engine for modeling and enforcing fine-grained access control inspired by Google Zanzibar.
|
| 10/06 | 8 |
Secret management platform for syncing secrets and configurations across teams and infrastructure while preventing leaks.
|
| 10/05 | 8 |
Kubernetes-native toolkit that continuously scans clusters and generates vulnerability, configuration, secrets, RBAC, compliance, and SBOM reports.
|
| 10/11 | 7 |
Manage dotfiles across multiple diverse machines securely.
|
| 10/11 | 7 |
Fast, efficient osquery management server implementing the osquery remote API as a TLS endpoint.
|
| 10/11 | 7 |
A Go-based website screenshot utility that uses Chrome Headless to capture web pages from the command line with optional reporting and saved results.
|
| 10/10 | 7 |
Embeddable Go library or standalone auth server with plugin-based, composable authentication and extensible hooks.
|
| 10/08 | 7 |
CI/CD compliance scanner for GitLab pipelines
|
| 10/08 | 7 |
Canonical JavaScript/TypeScript SDK for the Socket.dev API, providing package scoring, quota management, batch lookups, and dependency analysis with built-in request handling.
|
| 10/08 | 7 |
Rails-oriented HotCell sidecar isolates untrusted computation in an unprivileged container with strict resource limits and file-descriptor based RPC.
|
| 10/08 | 7 |
Platform for managing, structuring, visualizing, and sharing cyber threat intelligence using a STIX2-based knowledge schema.
|
| 10/07 | 7 |
API for checking port availability on specified hostnames or IP addresses to assist network troubleshooting and firewall validation.
|
| 10/06 | 7 |
Vulnerability scanner for container images and filesystems.
|
| 10/06 | 7 |
Securely share sensitive information with automatic expiration and deletion after a set number of views or duration.
|
| 10/06 | 7 |
Middleware for limiting repeated requests to public APIs and endpoints.
|
| 10/10 | 6 |
JSON.parse() drop-in replacement that protects against prototype poisoning via __proto__ and constructor.prototype keys.
|
| 10/09 | 6 |
Proxy that secures and simplifies access to infrastructure with outbound-only connections and integrated SSO.
|
| 10/09 | 6 |
High-level Go packages providing APIs for interacting with TPM 2.0 devices.
|
| 10/08 | 6 |
Platform for engineering teams to secure, manage, and deploy application secrets across environments.
|
| 10/06 | 6 |
End-to-end field-level encryption for TypeScript apps with zero-knowledge key management and searchable encrypted queries.
|
| 10/06 | 6 |
Autonomous AI pentesting platform that runs an end-to-end methodology and uses independent re-exploitation to verify and prove vulnerabilities.
|
| 10/07 | 5 |
Security-first personal AI assistant runtime providing multi-provider model access and multi-channel messaging integrations with local-first data control.
|
| 10/06 | 5 |
Windows-based, AI-powered all-in-one reverse engineering package manager for malware analysis, penetration testing, and education.
JavaScript
361☆
1285d old
#javascript
#security
#reverse-engineering
#penetration-testing
#awesome-list
|
| 10/04 | 5 |
JavaScript AST analysis tool for identifying potentially malicious code patterns.
|
| 10/10 | 3 |
Cybersecurity-focused domain-specific programming language with a dedicated virtual machine and IDE support.
|
| 10/06 | 3 |
Local-first EDR-style monitor tracking AI agent processes, file and network activity with per-agent risk scoring.
|
| 10/10 | 2 |
A network security appliance firmware and companion mobile and web apps for managing and monitoring home or small office networks.
|