mendel129's starred repositories

Awesome-CloudSec-Labs

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

Stargazers:1352Issues:0Issues:0

passbolt_api

Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!

Language:PHPLicense:AGPL-3.0Stargazers:4488Issues:0Issues:0

server

Bitwarden infrastructure/backend (API, database, Docker, etc).

Language:C#License:NOASSERTIONStargazers:14818Issues:0Issues:0

vaultwarden

Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs

Language:RustLicense:AGPL-3.0Stargazers:35038Issues:0Issues:0

amazon-cognito-passwordless-auth

Passwordless authentication with Amazon Cognito: FIDO2 (WebAuthn, support for Passkeys), Magic Link, SMS OTP Step Up

Language:TypeScriptLicense:Apache-2.0Stargazers:340Issues:0Issues:0

PSBits

Simple (relatively) things allowing you to dig a bit deeper than usual.

Language:CLicense:UnlicenseStargazers:3068Issues:0Issues:0

yatas

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

Language:GoLicense:Apache-2.0Stargazers:307Issues:0Issues:0

IRM

Incident Response Methodologies 2022

License:NOASSERTIONStargazers:894Issues:0Issues:0
License:NOASSERTIONStargazers:893Issues:0Issues:0

aws-customer-playbook-framework

This repository provides sample templates for security playbooks against various scenarios when using Amazon Web Services.

License:NOASSERTIONStargazers:500Issues:0Issues:0

security-labs-pocs

Proof of concept code for Datadog Security Labs referenced exploits.

Language:CLicense:NOASSERTIONStargazers:414Issues:0Issues:0

security-study-plan

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...

Stargazers:4211Issues:0Issues:0

DevSecOps

Ultimate DevSecOps library

License:MITStargazers:5438Issues:0Issues:0

DeTTECT

Detect Tactics, Techniques & Combat Threats

Language:SCSSLicense:GPL-3.0Stargazers:2013Issues:0Issues:0

gimme-aws-creds

A CLI that utilizes Okta IdP via SAML to acquire temporary AWS credentials

Language:PythonLicense:Apache-2.0Stargazers:914Issues:0Issues:0

IoT-Security-Verification-Standard-ISVS

OWASP IoT Security Verification Standard (ISVS)

Language:TeXLicense:NOASSERTIONStargazers:130Issues:0Issues:0

apk-mitm

🤖 A CLI application that automatically prepares Android APK files for HTTPS inspection

Language:TypeScriptLicense:MITStargazers:3630Issues:0Issues:0

cloudfox

Automating situational awareness for cloud penetration tests.

Language:GoLicense:MITStargazers:1854Issues:0Issues:0

APIKit

APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

Language:JavaLicense:GPL-3.0Stargazers:1806Issues:0Issues:0

jwt_tool

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Language:PythonLicense:GPL-3.0Stargazers:5175Issues:0Issues:0

paseto

Platform-Agnostic Security Tokens

Language:PHPLicense:NOASSERTIONStargazers:3231Issues:0Issues:0

prowler

Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more

Language:PythonLicense:Apache-2.0Stargazers:10007Issues:0Issues:0

aws-vault

A vault for securely storing and accessing AWS credentials in development environments

Language:GoLicense:MITStargazers:8280Issues:0Issues:0

awspx

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

Language:PythonLicense:GPL-3.0Stargazers:891Issues:0Issues:0

cloudgoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

Language:PythonLicense:BSD-3-ClauseStargazers:2828Issues:0Issues:0
Language:YARAStargazers:38Issues:0Issues:0

bad-practices

CISA's catalog of bad practices that are exceptionally risky.

Language:ShellLicense:CC0-1.0Stargazers:199Issues:0Issues:0

codechecker

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy

Language:PythonLicense:Apache-2.0Stargazers:2156Issues:0Issues:0

Adalanche

Active Directory ACL Visualizer and Explorer - who's really Domain Admin? (Commerical versions available from NetSection)

Language:GoLicense:AGPL-3.0Stargazers:1596Issues:0Issues:0