mendel129's starred repositories

vaultwarden

Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs

Language:RustLicense:AGPL-3.0Stargazers:33961Issues:231Issues:1931

server

The core infrastructure backend (API, database, Docker, etc).

Language:C#License:NOASSERTIONStargazers:14527Issues:207Issues:1129

cloud-custodian

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

Language:PythonLicense:Apache-2.0Stargazers:5258Issues:165Issues:4052

ThreatMapper

Open Source Cloud Native Application Protection Platform (CNAPP)

Language:TypeScriptLicense:Apache-2.0Stargazers:4671Issues:58Issues:571

passbolt_api

Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!

Language:PHPLicense:AGPL-3.0Stargazers:4426Issues:89Issues:429

pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Language:PythonLicense:BSD-3-ClauseStargazers:4099Issues:110Issues:122

htmlpurifier

Standards compliant HTML filter written in PHP

Language:PHPLicense:LGPL-2.1Stargazers:2996Issues:65Issues:237

security-research

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

Language:CLicense:Apache-2.0Stargazers:2886Issues:233Issues:13

coraza

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library

Language:GoLicense:Apache-2.0Stargazers:1891Issues:33Issues:317

dnsteal

DNS Exfiltration tool for stealthily sending files over DNS requests.

Language:PythonLicense:GPL-2.0Stargazers:1671Issues:77Issues:10

Awesome-CloudSec-Labs

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

cloudformation-guard

Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

Language:RustLicense:Apache-2.0Stargazers:1245Issues:40Issues:209

certspotter

Certificate Transparency Log Monitor

Language:GoLicense:MPL-2.0Stargazers:930Issues:32Issues:54

saas-attacks

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown

ZeusCloud

Open Source Cloud Security

Language:TypeScriptLicense:Apache-2.0Stargazers:674Issues:14Issues:53

m5stick-nemo

M5 Stick C firmware for high-tech pranks

Language:CLicense:NOASSERTIONStargazers:593Issues:29Issues:103

confsec

Security, hacking conferences (list)

aws-security-survival-kit

Bare minimum AWS Security Alerting and Configuration

Language:MakefileLicense:GPL-3.0Stargazers:440Issues:18Issues:17

aws-iot-device-sdk-python-v2

Next generation AWS IoT Client SDK for Python using the AWS Common Runtime

Language:PythonLicense:Apache-2.0Stargazers:387Issues:30Issues:199

threat-composer

A simple threat modeling tool to help humans to reduce time-to-value when threat modeling

Language:TypeScriptLicense:Apache-2.0Stargazers:384Issues:13Issues:6

inverting-proxy

Reverse proxy that inverts the direction of traffic

Language:GoLicense:Apache-2.0Stargazers:249Issues:16Issues:22

jupyter-notebook-for-incident-response

A library of Incident Response notebooks using Jupyter. We will show how you can leverage pre-defined notebook files to guide your incident responders in identifying, containing, eradicating, and recovering from an incident.

Language:Jupyter NotebookLicense:MIT-0Stargazers:134Issues:13Issues:0
Language:SCSSStargazers:133Issues:6Issues:0
Language:PythonLicense:AGPL-3.0Stargazers:126Issues:3Issues:0

jwt-webtool

Source code repo for the online JWT webtool.

Language:JavaScriptLicense:Apache-2.0Stargazers:119Issues:8Issues:10

vault-policy-guide

A brief guide to help illustrate some of the more nuanced aspects of HashiCorp Vault's policies.

Language:HCLLicense:CC-BY-SA-4.0Stargazers:116Issues:5Issues:1

aws-guard-rules-registry

Rules Registry for Compliance Frameworks

Language:PythonLicense:Apache-2.0Stargazers:102Issues:13Issues:188
Language:GoLicense:Apache-2.0Stargazers:101Issues:3Issues:3

security-analysis-tool

Security Analysis Tool (SAT) analyzes customer's Databricks account and workspace security configurations and provides recommendations that help them follow Databrick's security best practices. When a customer runs SAT, it will compare their workspace configurations against a set of security best practices and delivers a report.

Language:PythonLicense:NOASSERTIONStargazers:60Issues:4Issues:34

hakrwatch

M5StickC watch with a hacker's touch

Language:CLicense:NOASSERTIONStargazers:17Issues:2Issues:8