Moein Fatehi's starred repositories

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Language:GoLicense:Apache-2.0Stargazers:21743Issues:169Issues:2513

cilium

eBPF-based Networking, Security, and Observability

Language:GoLicense:Apache-2.0Stargazers:18960Issues:313Issues:9338

kubescape

Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

Language:GoLicense:Apache-2.0Stargazers:9836Issues:98Issues:465

engineering-management

A collection of inspiring resources related to engineering management and tech leadership

Language:ShellLicense:MITStargazers:7356Issues:254Issues:3

wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Language:DockerfileLicense:CC-BY-SA-4.0Stargazers:6820Issues:319Issues:340

slither

Static Analyzer for Solidity and Vyper

Language:PythonLicense:AGPL-3.0Stargazers:5083Issues:68Issues:1154

ThreatMapper

Open Source Cloud Native Application Protection Platform (CNAPP)

Language:TypeScriptLicense:Apache-2.0Stargazers:4671Issues:58Issues:571

echidna

Ethereum smart contract fuzzer

Language:SolidityLicense:AGPL-3.0Stargazers:2605Issues:60Issues:571

Damn-Vulnerable-GraphQL-Application

Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.

Language:JavaScriptLicense:MITStargazers:1443Issues:27Issues:31

solidity-security-blog

Comprehensive list of known attack vectors and common anti-patterns

publications

Publications from Trail of Bits

Language:PythonLicense:CC-BY-SA-4.0Stargazers:1337Issues:139Issues:11

panoramix

Ethereum decompiler

Language:PythonLicense:MITStargazers:767Issues:36Issues:35

Smart-Contract-Security-Audits

Certified Smart Contract Audits for Ethereum, Solana, Near, Cardano, Aptos, Sui, Binance Smart Chain, Fantom, EOS, Tezos by softstack (formerly Chainsulting)

Language:HTMLStargazers:758Issues:225Issues:0

verified-smart-contracts

Smart contracts which are formally verified

Language:SolidityLicense:NOASSERTIONStargazers:705Issues:50Issues:18

Awesome-Smart-Contract-Security

A curated list of Smart Contract Security materials and resources For Researchers

SCSVS

Smart Contract Security Verification Standard

securify2

Securify v2.0

Language:SolidityLicense:Apache-2.0Stargazers:573Issues:25Issues:37

smartbugs

SmartBugs: A Framework to Analyze Ethereum Smart Contracts

Language:PythonLicense:Apache-2.0Stargazers:540Issues:17Issues:95

balancer-v2-monorepo

Balancer V2 Monorepo

Language:TypeScriptLicense:GPL-3.0Stargazers:293Issues:34Issues:450

abci

DEPRECATED: Merged into https://github.com/tendermint/tendermint under `abci`

Language:GoLicense:NOASSERTIONStargazers:254Issues:40Issues:112

blockchains-auditing

๐Ÿ‘พ ๐˜€๐—ฎ๐˜ƒ๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐—ณ๐˜‚๐˜๐˜‚๐—ฟ๐—ฒ ๐—ผ๐—ณ $ ๐—ณ๐—ผ๐—ฟ ๐—ณ๐˜‚๐—ป ๐—ผ๐—ฟ $ - ๐—บ๐˜† ๐—ป๐—ผ๐˜๐—ฒ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฎ๐—ฟ๐˜…๐—ถ๐˜ƒ๐˜€ ๐—ณ๐—ฟ๐—ผ๐—บ ๐—ฎ๐—ป ๐—ผ๐—ป๐—ด๐—ผ๐—ถ๐—ป๐—ด ๐—ฎ๐—ป๐—ฑ ๐—ฐ๐—ผ๐—บ๐—ฝ๐—ฟ๐—ฒ๐—ต๐—ฒ๐—ป๐˜€๐—ถ๐˜ƒ๐—ฒ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฟ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต

License:NOASSERTIONStargazers:129Issues:16Issues:0

public-audits

Collection of public security reviews

awesome-chatgpt-plugins

An awesome & curated list of best plugins for ChatGPT

audits

Security Audits by Informal Systems

Language:TLALicense:Apache-2.0Stargazers:15Issues:28Issues:0

backup-finder

A burp suite extension that reviews backup, old, temporary and unreferenced files on web server for sensitive information (OWASP OTG-CONFIG-004)

Language:JavaLicense:GPL-3.0Stargazers:10Issues:3Issues:0