There are 124 repositories under security-audit topic.
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
A static analysis security vulnerability scanner for Ruby on Rails applications
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
Vulnerability scanner written in Go which uses the data provided by https://osv.dev
the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, variable tracking, deobfuscation, python&java scripts, device memory extraction, data decryption, and encryption, etc.
Advanced vulnerability scanning with Nmap NSE
Cloud Security Posture Management (CSPM)
Find leaked secrets via github search
Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
Patch-level verification for Bundler
DEPRECATED, bettercap developement moved here: https://github.com/bettercap/bettercap
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
🐀 Small chrome extension to monitor (and optionally block) other extensions' network calls
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)
Directory Services Internals (DSInternals) PowerShell Module and Framework
Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.
A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.