Security
安全工具与实践
ossec/ossec-hids
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
google/google-ctf
Google CTF
ClearURLs/Addon
ClearURLs is an add-on based on the new WebExtensions technology and will automatically remove tracking elements from URLs to help protect your privacy.
cheatsnake/backend-cheats
📃 White paper for Backend developers
Hack-with-Github/Free-Security-eBooks
Free Security and Hacking eBooks
hahwul/WebHackersWeapons
⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting
andresriancho/w3af
w3af: web application attack and audit framework, the open source web vulnerability scanner.
microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
DefectDojo/django-DefectDojo
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
cilium/tetragon
eBPF-based Security Observability and Runtime Enforcement
nicocha30/ligolo-ng
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
Security-Onion-Solutions/securityonion
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
urbanadventurer/Android-PIN-Bruteforce
Unlock an Android phone (or device) by bruteforcing the lockscreen PIN. Turn your Kali Nethunter phone into a bruteforce PIN cracker for Android devices! (no root, no adb)
aya-rs/aya
Aya is an eBPF library for the Rust programming language, built with a focus on developer experience and operability.
0x4D31/awesome-threat-detection
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
forter/security-101-for-saas-startups
security tips for startups
AliyunContainerService/pouch
An Efficient Enterprise-class Container Engine
build-trust/ockam
Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications – at massive scale.
slowmist/Knowledge-Base
Knowledge Base 慢雾安全团队知识库
ReversecLabs/drozer
The Leading Security Assessment Framework for Android.
openziti/zrok
Secure internet sharing made simple.
aquasecurity/tracee
Linux Runtime Security and Forensics using eBPF
YauhenKavalchuk/interview-questions
Популярные HTML / CSS / JavaScript / ECMAScript / TypeScript / React / Vue / Angular / Node вопросы на интервью и ответы на них (https://tinyurl.com/wxysrpsy)
google/santa
A binary authorization and monitoring system for macOS
cerbos/cerbos
Cerbos is the open core, language-agnostic, scalable authorization solution that makes user permissions and authorization simple to implement and manage by writing context-aware access control policies for your application resources.
firmianay/CTF-All-In-One
CTF竞赛权威指南
M66B/FairEmail
Fully featured, open source, privacy friendly email app for Android
HotCakeX/Harden-Windows-Security
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Personal, Enterprise, Government and Military security levels | SLSA Level 3 Compliant for Secure Development and Build Process | Apps Available on MS Store✨
projectdiscovery/interactsh
An OOB interaction gathering server and client library
zer0yu/Awesome-CobaltStrike
List of Awesome CobaltStrike Resources