dragon040's starred repositories

static-analysis

⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.

Language:RustLicense:MITStargazers:13225Issues:0Issues:0

kubesploit

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Language:GoLicense:GPL-3.0Stargazers:1115Issues:0Issues:0

Awesome-Hacking

A collection of various awesome lists for hackers, pentesters and security researchers

License:CC0-1.0Stargazers:83219Issues:0Issues:0

dvka

Damn Vulnerable Kubernetes App (DVKA) is a series of apps deployed on Kubernetes that are damn vulnerable.

Language:CSSStargazers:55Issues:0Issues:0

aws-secrets-manager-rotation-lambdas

Contains Lambda functions to be used for automatic rotation of secrets stored in AWS Secrets Manager

Language:PythonLicense:MIT-0Stargazers:323Issues:0Issues:0

www-project-ai-security-and-privacy-guide

OWASP Foundation Web Respository

Language:HTMLStargazers:199Issues:0Issues:0

tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!

Language:HTMLLicense:NOASSERTIONStargazers:2031Issues:0Issues:0

langkit

🔍 LangKit: An open-source toolkit for monitoring Large Language Models (LLMs). 📚 Extracts signals from prompts & responses, ensuring safety & security. 🛡️ Features include text quality, relevance metrics, & sentiment analysis. 📊 A comprehensive tool for LLM observability. 👀

Language:Jupyter NotebookLicense:Apache-2.0Stargazers:822Issues:0Issues:0

scorecard

OpenSSF Scorecard - Security health metrics for Open Source

Language:GoLicense:Apache-2.0Stargazers:4452Issues:0Issues:0

vmclarity

VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities

Language:GoLicense:Apache-2.0Stargazers:100Issues:0Issues:0

secureCodeBox

secureCodeBox (SCB) - continuous secure delivery out of the box

Language:JavaScriptLicense:NOASSERTIONStargazers:771Issues:0Issues:0

trufflehog

Find, verify, and analyze leaked credentials

Language:GoLicense:AGPL-3.0Stargazers:15757Issues:0Issues:0

AppleJuice

Apple BLE proximity pairing message spoofing

Language:PythonLicense:Apache-2.0Stargazers:1667Issues:0Issues:0

publications

This repository contains examples of information security policies, GDPR protocols and an operational security guide with examples of best practices.

License:CC0-1.0Stargazers:5Issues:0Issues:0

lucha

A CLI that scans for sensitive data in source code

Language:GoLicense:MPL-2.0Stargazers:13Issues:0Issues:0

shs

A command line application that calculates the security health of an application, system, or code base and returns a single score.

Language:GoLicense:MPL-2.0Stargazers:7Issues:0Issues:0

ci-integrations

Example scripts to run Tinfoil Security via your CI

Language:ShellLicense:MITStargazers:6Issues:0Issues:0

ctf-katana

This repository aims to hold suggestions (and hopefully/eventually code) for CTF challenges. The "project" is nicknamed Katana.

Stargazers:2547Issues:0Issues:0

vapi

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Language:HTMLLicense:GPL-3.0Stargazers:1158Issues:0Issues:0

shipfast-api-protection

Learn practical Mobile and API security techniques: API Key, Static and Dynamic HMAC, Dynamic Certificate Pinning, and Mobile App Attestation.

Language:KotlinLicense:MITStargazers:73Issues:0Issues:0

Key-Checker

Go scripts for checking API key / access token validity

Language:GoLicense:MITStargazers:210Issues:0Issues:0

bugbounty-cheatsheet

A list of interesting payloads, tips and tricks for bug bounty hunters.

License:CC-BY-SA-4.0Stargazers:5803Issues:0Issues:0

APAC-Conferences

A community contributed consolidated list of InfoSec meetups in the Asia Pacific region.

License:GPL-3.0Stargazers:153Issues:0Issues:0

github-search

Tools to perform basic search on GitHub.

Stargazers:5Issues:0Issues:0

bugbounty-cheatsheet

A list of interesting payloads, tips and tricks for bug bounty hunters.

Stargazers:27Issues:0Issues:0

hacks

Small snippets and scripts which I use

Language:ShellStargazers:33Issues:0Issues:0

keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

Stargazers:4897Issues:0Issues:0

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

Language:PHPLicense:MITStargazers:57115Issues:0Issues:0

vulnado

Purposely vulnerable Java application to help lead secure coding workshops

Language:JavaLicense:NOASSERTIONStargazers:165Issues:0Issues:0