mendel129's starred repositories

cloud-custodian

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

Language:PythonLicense:Apache-2.0Stargazers:5303Issues:164Issues:4072

ThreatMapper

Open Source Cloud Native Application Protection Platform (CNAPP)

Language:TypeScriptLicense:Apache-2.0Stargazers:4720Issues:57Issues:576

pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Language:PythonLicense:BSD-3-ClauseStargazers:4203Issues:109Issues:124

security-research

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

Language:CLicense:Apache-2.0Stargazers:3172Issues:240Issues:13

htmlpurifier

Standards compliant HTML filter written in PHP

Language:PHPLicense:LGPL-2.1Stargazers:3022Issues:65Issues:238

coraza

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library

Language:GoLicense:Apache-2.0Stargazers:2007Issues:33Issues:324

dnsteal

DNS Exfiltration tool for stealthily sending files over DNS requests.

Language:PythonLicense:GPL-2.0Stargazers:1677Issues:77Issues:10

cloudformation-guard

Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

Language:RustLicense:Apache-2.0Stargazers:1258Issues:40Issues:211

saas-attacks

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown

certspotter

Certificate Transparency Log Monitor

Language:GoLicense:MPL-2.0Stargazers:944Issues:33Issues:60

ZeusCloud

Open Source Cloud Security

Language:TypeScriptLicense:Apache-2.0Stargazers:681Issues:14Issues:53

m5stick-nemo

M5 Stick C firmware for high-tech pranks

Language:CLicense:NOASSERTIONStargazers:653Issues:30Issues:107

awesome-secure-defaults

Awesome secure by default libraries to help you eliminate bug classes!

confsec

Security, hacking conferences (list)

aws-security-survival-kit

Bare minimum AWS Security Alerting and Configuration

Language:MakefileLicense:GPL-3.0Stargazers:440Issues:18Issues:17

threat-composer

A simple threat modeling tool to help humans to reduce time-to-value when threat modeling

Language:TypeScriptLicense:Apache-2.0Stargazers:411Issues:14Issues:8

aws-iot-device-sdk-python-v2

Next generation AWS IoT Client SDK for Python using the AWS Common Runtime

Language:PythonLicense:Apache-2.0Stargazers:395Issues:30Issues:199

inverting-proxy

Reverse proxy that inverts the direction of traffic

Language:GoLicense:Apache-2.0Stargazers:250Issues:16Issues:22
Language:SCSSStargazers:153Issues:6Issues:0
Language:PythonLicense:AGPL-3.0Stargazers:141Issues:3Issues:0

jupyter-notebook-for-incident-response

A library of Incident Response notebooks using Jupyter. We will show how you can leverage pre-defined notebook files to guide your incident responders in identifying, containing, eradicating, and recovering from an incident.

Language:Jupyter NotebookLicense:MIT-0Stargazers:137Issues:13Issues:0

vault-policy-guide

A brief guide to help illustrate some of the more nuanced aspects of HashiCorp Vault's policies.

Language:HCLLicense:CC-BY-SA-4.0Stargazers:127Issues:5Issues:1

jwt-webtool

Source code repo for the online JWT webtool.

Language:JavaScriptLicense:Apache-2.0Stargazers:126Issues:8Issues:10
Language:GoLicense:Apache-2.0Stargazers:106Issues:3Issues:3

aws-guard-rules-registry

Rules Registry for Compliance Frameworks

Language:PythonLicense:Apache-2.0Stargazers:103Issues:13Issues:189

security-analysis-tool

Security Analysis Tool (SAT) analyzes customer's Databricks account and workspace security configurations and provides recommendations that help them follow Databrick's security best practices. When a customer runs SAT, it will compare their workspace configurations against a set of security best practices and delivers a report.

Language:PythonLicense:NOASSERTIONStargazers:74Issues:5Issues:35

terraform-aws-ca

Terraform module for serverless certificate authority on AWS

Language:PythonLicense:NOASSERTIONStargazers:65Issues:4Issues:11
Language:PythonLicense:MIT-0Stargazers:34Issues:0Issues:0

hakrwatch

M5StickC watch with a hacker's touch

Language:CLicense:NOASSERTIONStargazers:17Issues:2Issues:8

cloud-ca

Cloud CA built using AWS CA Terraform Module

Language:PythonLicense:Apache-2.0Stargazers:7Issues:0Issues:0