Skip to content

About

Discover an awesome compilation of tools, libraries, and resources for robust security. From network to web security, find everything you need to enhance your security expertise.

Topics

Resources

Code of conduct

Contributing

Stars

5 stars

Watchers

2 watching

Forks

Latest commit

Β 

History

23 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Awesome Security

Awesome License: MIT

A curated collection of fantastic software, libraries, documents, books, and resources dedicated to security. From network and endpoint protection to threat intelligence and web security β€” a comprehensive list to enhance your security knowledge and practices.


🌐 Network

πŸ” Scanning / Pentesting

  • Metasploit Framework – tool for developing and executing exploit code against a remote target machine.
  • Nmap – free and open source utility for network discovery and security auditing.
  • Nuclei – fast, customizable vulnerability scanner based on simple YAML-based templates.
  • OpenVAS – framework of services and tools offering comprehensive vulnerability scanning and management.
  • pig – Linux packet crafting tool.
  • Pompem – open source tool to automate the search for exploits in major databases.
  • scapy – Python-based interactive packet manipulation program and library.

πŸ“Š Monitoring / Logging

  • Fibratus – tool for exploration and tracing of the Windows kernel activity.
  • httpry – specialized packet sniffer for displaying and logging HTTP traffic.
  • justniffer – network protocol analyzer that captures traffic and produces customized logs.
  • ngrep – pcap-aware tool applying grep-like features to the network layer.
  • ntopng – network traffic probe showing usage similar to the Unix top command.
  • passivedns – tool to collect DNS records passively for incident handling and NSM.
  • sagan – multi-threaded, real-time log analysis engine with a Snort-like rule set.

πŸ›‘οΈ IDS / IPS / Host IDS / Host IPS

  • AIEngine – next generation interactive Python/Ruby/Java/Lua packet inspection engine with NIDS functionality.
  • Denyhosts – thwart SSH dictionary-based and brute force attacks.
  • Fail2Ban – scans log files and takes action on IPs that show malicious behavior.
  • Falco – cloud-native runtime security tool for detecting unexpected behavior in Linux systems.
  • Lynis – open source security auditing tool for Linux/Unix.
  • OSSEC – comprehensive open source HIDS performing log analysis, file integrity, rootkit detection and alerting.
  • Security Onion – Linux distro for intrusion detection, network security monitoring, and log management.
  • Snort – free and open source network intrusion prevention and detection system.
  • SSHGuard – software protecting services in addition to SSH, written in C.
  • sshwatch – IPS for SSH written in Python, gathers attacker information during attacks.
  • Stealth – file integrity checker that leaves virtually no sediment on the monitored host.
  • Suricata – high performance Network IDS, IPS and Network Security Monitoring engine.
  • Wazuh – open source security platform unifying SIEM, XDR, and cloud security capabilities.
  • Zeek – powerful network analysis framework (formerly Bro).

🍯 Honey Pot / Honey Net

  • Amun – Python-based low-interaction honeypot.
  • awesome-honeypots – the canonical awesome honeypot list.
  • Bifrozt – NAT device that works as a transparent SSHv2 proxy between an attacker and your honeypot.
  • Conpot – ICS/SCADA low-interactive server-side honeypot.
  • Cuckoo Sandbox – open source software for automating analysis of suspicious files.
  • Dionaea – nepenthes successor honeypot embedding Python as scripting language.
  • Glastopf – honeypot emulating thousands of vulnerabilities to gather web attack data.
  • HoneyDrive – premier honeypot Linux distro with over 10 pre-installed honeypot packages.
  • HoneyPy – low to medium interaction honeypot, easy to deploy and extend.
  • HonSSH – high-interaction honeypot sitting between an attacker and a honeypot over SSH.
  • Kippo – medium interaction SSH honeypot for logging brute force attacks.
  • Kojoney – low level interaction honeypot emulating an SSH server.

πŸ—‚οΈ Full Packet Capture / Forensic

  • Dshell – network forensic analysis framework enabling rapid development of dissection plugins.
  • Moloch – open source large scale IPv4 packet capturing, indexing and database system.
  • OpenFPC – lightweight full-packet network traffic recorder and buffering system.
  • stenographer – packet capture solution that spools all packets to disk for fast subset access.
  • tcpflow – captures TCP connection data and stores it for protocol analysis and debugging.
  • Xplico – open source Network Forensic Analysis Tool extracting applications data from captures.

πŸ”¬ Sniffer

  • netsniff-ng – free Linux networking toolkit using zero-copy mechanisms for high performance.
  • Wireshark – free and open-source packet analyzer with graphical front-end and filtering options.

πŸ“‹ Security Information & Event Management

  • FIR – Fast Incident Response, a cybersecurity incident management platform.
  • OSSIM – AT&T Cybersecurity SIEM with event collection, normalization, and correlation.
  • Prelude – universal SIEM collecting, normalizing, aggregating and correlating security events.

πŸ” VPN

  • OpenVPN – open source VPN using a custom security protocol utilizing SSL/TLS for key exchange.
  • WireGuard – extremely simple yet fast and modern VPN utilizing state-of-the-art cryptography.

⚑ Fast Packet Processing

  • DPDK – set of libraries and drivers for fast packet processing.
  • netmap – framework for high speed packet I/O available for FreeBSD, Linux and Windows.
  • PACKET_MMAP/TPACKET/AF_PACKET – Linux kernel mechanism for high-performance packet capture and transmission.
  • PF_RING – network socket dramatically improving packet capture speed.
  • PF_RING ZC (Zero Copy) – flexible packet processing framework achieving line rate at any packet size.
  • PFQ – functional networking framework for efficient packet capture and in-kernel processing.

πŸ”₯ Firewall

  • fwknop – protects ports via Single Packet Authorization.
  • OPNsense – open source, easy-to-use FreeBSD-based firewall and routing platform.
  • pfSense – firewall and Router FreeBSD distribution.

πŸ“§ Anti-Spam

  • SpamAssassin – powerful and popular email spam filter employing a variety of detection techniques.

🐳 Docker Images for Penetration Testing & Security


πŸ’» Endpoint

🦠 Anti-Virus / Anti-Malware

  • ClamAV – open source antivirus engine for detecting trojans, viruses, malware and other threats.
  • Linux Malware Detect – malware scanner for Linux designed around threats in shared hosted environments.

🧹 Content Disarm & Reconstruct

  • DocBleach – open-source CDR software sanitizing Office, PDF and RTF documents.

βš™οΈ Configuration Management

  • Rudder – web-driven, role-based solution for IT Infrastructure Automation and Compliance.

πŸ”‘ Authentication

πŸ“± Mobile / Android / iOS

πŸ” Forensics

  • grr – GRR Rapid Response is an incident response framework focused on remote live forensics.
  • ir-rescue – Windows Batch and Unix Bash scripts to collect host forensic data during incident response.
  • mig – platform to perform investigative surgery on remote endpoints in parallel.
  • Velociraptor – tool for collecting host-based state information using Velociraptor Query Language.
  • Volatility – Python-based memory extraction and analysis framework.

πŸ•΅οΈ Threat Intelligence

  • abuse.ch – tracks Command&Control servers and provides domain and IP blocklists.
  • AlienVault Open Threat Exchange – collaborative threat intelligence network.
  • AutoShun – Snort plugin correlating attacks across sensors, honeypots and mail filters worldwide.
  • CIFv2 – cyber threat intelligence management system combining malicious threat information from many sources.
  • CriticalStack – free aggregated threat intel for the Zeek network security monitoring platform.
  • DNS-BH – listing of domains known to propagate malware and spyware.
  • Emerging Threats - Open Source – open source community providing Suricata and Snort rules, firewall rules and IDS rulesets.
  • FireEye OpenIOCs – FireEye publicly shared Indicators of Compromise.
  • IntelMQ – solution for CERTs for collecting and processing security feeds using a message queue protocol.
  • Internet Storm Center – free analysis and warning service for Internet threats.
  • MISP – open source threat intelligence and sharing platform.
  • OpenVAS NVT Feed – public feed of Network Vulnerability Tests containing 35,000+ NVTs.
  • PhishTank – collaborative clearing house for phishing data with open API.
  • Project Honey Pot – distributed system for identifying spammers and harvesting bots.
  • SBL / XBL / PBL / DBL / DROP / ROKSO – Spamhaus real-time anti-spam protection and blocklists.
  • TheHive – scalable, open source security incident response platform.
  • Tor Bulk Exit List – CollecTor data-collecting service providing Tor network data.
  • virustotal – free online service analyzing files and URLs for malicious content detected by 70+ AV engines.

🌍 Web

🏒 Organization

  • OWASP – the Open Web Application Security Project, focused on improving the security of software.

πŸ›‘οΈ Web Application Firewall

  • ironbee – open source universal web application security sensor and WAF framework.
  • ModSecurity – toolkit for real-time web application monitoring, logging, and access control.
  • NAXSI – open-source, high performance, low rules maintenance WAF for NGINX.
  • sql_firewall – SQL Firewall extension for PostgreSQL.

πŸ” Scanning / Pentesting

  • ACSTIS – scans web applications for AngularJS Client-Side Template Injection vulnerabilities.
  • Infection Monkey – semi-automatic pen testing tool for mapping and pen-testing networks.
  • Nikto – open source web server scanner performing comprehensive tests against web servers.
  • OWASP Testing Checklist v4 – list of controls to test during a web vulnerability assessment.
  • PTF – Penetration Testers Framework providing modular support for up-to-date tools.
  • Recon-ng – full-featured Web Reconnaissance framework written in Python.
  • sqlmap – open source penetration testing tool automating detection and exploitation of SQL injection.
  • w3af – Web Application Attack and Audit Framework.
  • ZAP – OWASP Zed Attack Proxy, easy-to-use integrated penetration testing tool.

⚑ Runtime Application Self-Protection

  • Sqreen – Runtime Application Self-Protection solution instrumenting and monitoring the app at runtime.

πŸ‘¨β€πŸ’» Development

  • OAuth 2 in Action – book teaching practical use and deployment of OAuth 2.
  • Secure by Design – book identifying design patterns and coding styles that reduce security vulnerabilities.
  • Securing DevOps – book exploring how DevOps and Security techniques apply together for safer cloud services.
  • Semgrep – fast, open source static analysis tool for finding bugs and enforcing code standards.
  • Understanding API Security – free eBook on how APIs are put together and how OAuth protects them.

🎯 Usability


πŸ“Š Big Data

  • Apache Metron – integrates open source big data technologies for centralized security monitoring and analysis.
  • Apache Spot – open source software for leveraging insights from flow and packet analysis.
  • binarypig – scalable binary data extraction in Hadoop for malware processing and analytics.
  • data_hacking – examples using IPython, Pandas, and Scikit Learn to get the most out of security data.
  • hadoop-pcap – Hadoop library to read packet capture (PCAP) files.
  • OpenSOC – integrates open source big data technologies for centralized security monitoring.
  • Workbench – scalable Python framework for security research and development teams.

πŸ—„οΈ Datastores

  • aws-vault – store AWS credentials in the OSX Keychain or an encrypted file.
  • blackbox – safely store secrets in a VCS repo using GPG.
  • chamber – store secrets using AWS KMS and SSM Parameter Store.
  • confidant – stores secrets in AWS DynamoDB, encrypted at rest and integrated with IAM.
  • credstash – store secrets using AWS KMS and DynamoDB.
  • dotgpg – tool for backing up and versioning production secrets or shared passwords securely.
  • passbolt – open source, extensible password manager based on OpenPGP.
  • redoctober – server for two-man rule style file encryption and decryption.
  • Safe – a Vault CLI making reading and writing to Vault easier.
  • Sops – editor of encrypted files supporting YAML, JSON and BINARY formats with AWS KMS and PGP.
  • Vault – encrypted datastore secure enough to hold environment and application secrets.

πŸš€ DevOps

  • Checkov – static code analysis tool for infrastructure-as-code detecting security misconfigurations.
  • Securing DevOps – book on security techniques for DevOps reviewing state-of-the-art practices.
  • tfsec – static analysis security scanner for Terraform code.

πŸ–₯️ Operating Systems

🌐 Online Resources


☸️ Kubernetes Security

  • Falco – cloud-native runtime security detecting unexpected behavior and configuration changes.
  • Kube-bench – checks whether Kubernetes is deployed according to CIS security benchmarks.
  • Kube-hunter – security scanner discovering vulnerabilities and security issues in Kubernetes clusters.
  • Kubernetes CIS Benchmark – official CIS benchmark with security configuration guidelines for Kubernetes.
  • Kubesec – scans Kubernetes resource manifests for security issues, providing risk scores.
  • Open Policy Agent (OPA) – general-purpose policy engine for fine-grained, context-aware policies in Kubernetes.
  • Trivy – comprehensive vulnerability scanner for container images, file systems and Kubernetes clusters.

☁️ Cloud Security

  • Azure Defender for Cloud – Microsoft Azure's unified security management with advanced threat protection.
  • Cloud Custodian – cloud security policy automation tool managing governance across cloud environments.
  • Cloud Security Alliance – provides best practices and security guidance for cloud computing environments.
  • GCP Security Command Center – Google Cloud's security and risk management platform for threat detection and compliance.
  • Prowler – open source cloud security tool for AWS, Azure and GCP security assessments and audits.
  • ScoutSuite – multi-cloud security auditing tool providing comprehensive security posture assessments.

πŸ› Vulnerability Management

  • Grype – vulnerability scanner for container images and filesystems.
  • Nessus – widely used commercial vulnerability scanner.
  • OpenVAS – open source vulnerability scanner.
  • Qualys Community Edition – free version of Qualys vulnerability scanner.
  • Rapid7 Nexpose – vulnerability and risk management scanner.
  • Vuls – vulnerability scanner for Linux, FreeBSD and containers.

πŸ‘€ Identity / Access Management


⚑ Serverless Security


πŸ“š Other Awesome Lists


Contributing

See CONTRIBUTING.md for guidelines.

License

MIT Β© Think Cube

About

Discover an awesome compilation of tools, libraries, and resources for robust security. From network to web security, find everything you need to enhance your security expertise.

Topics

Resources

Code of conduct

Contributing

Stars

5 stars

Watchers

2 watching

Forks

Contributors