TopGit

Dự án mã nguồn mở Security tốt nhất

Công cụ bảo mật mã nguồn mở trên GitHub — scanner, framework kiểm thử xâm nhập, quản lý secret và tiện ích gia cố, xếp theo sao và có review từ TopGit.

Repo Security hàng đầu

H
Hack-with-Github/Awesome-Hacking

Awesome Hacking is a GitHub-hosted index of other security awesome-lists, maintained by Hack-with-Github: 117,538 stars, 10,586 forks, and two tables of external links split between primary awesome-list repositories and standalone reference tools. It doesn't teach anything itself - every row is a one-line pointer to someone else's list, spanning Android security to prompt injection against AI systems, released under CC0-1.0.

3638117.5k10.6k
# android# awesome# bug-bounty
10.6kĐọc review
D
danielmiessler/SecLists

SecLists is a collection of security lists designed to aid penetration testers and ethical hackers. It centralizes various data types, including usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, and web shells, making it a comprehensive resource for conducting security assessments and identifying vulnerabilities. The project aims to provide immediate access to necessary lists upon setting up a new testing environment.

3631072.6k25.1k
PHP
25.1kĐọc review
G
goauthentik/authentik

authentik is an open-source Identity Provider (IdP) designed for modern Single Sign-On (SSO), supporting protocols like SAML, OAuth2/OIDC, LDAP, and RADIUS. It's built for self-hosting, suitable for deployments ranging from small test environments to large production clusters. Installation options include Docker Compose, Kubernetes via Helm charts, AWS CloudFormation, and a one-click deployment through the DigitalOcean Marketplace. The project also offers an enterprise solution for organizations looking to replace commercial identity providers, with examples including Okta, Auth0, Entra ID, and Ping Identity.

1.2k22.8k1.8k
Python
# authentication# authentik# authorization
1.8kĐọc review
C
cloudfoundry/uaa

CloudFoundry's UAA (User Account and Authentication) Server is a multi-tenant identity management service implemented as a Spring MVC web application in Java. Its primary role is to function as an OAuth2 provider, issuing tokens for client applications acting on behalf of users, and it also handles user authentication and single sign-on. While integral to Cloud Foundry, the UAA server can operate as a standalone OAuth2 and partial OpenID Connect server, offering standard endpoints for authorization, token issuance, token verification, and user information. It supports SCIM for user provisioning and can be run with HSQLDB, MySQL, or PostgreSQL, deployable in containers like Tomcat or directly via Gradle.

621.6k842
Java
# java# oauth# oauth2
842Đọc review

Vừa được đánh giá

G
goauthentik/authentik

authentik is an open-source Identity Provider (IdP) designed for modern Single Sign-On (SSO), supporting protocols like SAML, OAuth2/OIDC, LDAP, and RADIUS. It's built for self-hosting, suitable for deployments ranging from small test environments to large production clusters. Installation options include Docker Compose, Kubernetes via Helm charts, AWS CloudFormation, and a one-click deployment through the DigitalOcean Marketplace. The project also offers an enterprise solution for organizations looking to replace commercial identity providers, with examples including Okta, Auth0, Entra ID, and Ping Identity.

1.2k22.8k1.8k
Python
# authentication# authentik# authorization
1.8kĐọc review
D
danielmiessler/SecLists

SecLists is a collection of security lists designed to aid penetration testers and ethical hackers. It centralizes various data types, including usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, and web shells, making it a comprehensive resource for conducting security assessments and identifying vulnerabilities. The project aims to provide immediate access to necessary lists upon setting up a new testing environment.

3631072.6k25.1k
PHP
25.1kĐọc review
C
cloudfoundry/uaa

CloudFoundry's UAA (User Account and Authentication) Server is a multi-tenant identity management service implemented as a Spring MVC web application in Java. Its primary role is to function as an OAuth2 provider, issuing tokens for client applications acting on behalf of users, and it also handles user authentication and single sign-on. While integral to Cloud Foundry, the UAA server can operate as a standalone OAuth2 and partial OpenID Connect server, offering standard endpoints for authorization, token issuance, token verification, and user information. It supports SCIM for user provisioning and can be run with HSQLDB, MySQL, or PostgreSQL, deployable in containers like Tomcat or directly via Gradle.

621.6k842
Java
# java# oauth# oauth2
842Đọc review
H
Hack-with-Github/Awesome-Hacking

Awesome Hacking is a GitHub-hosted index of other security awesome-lists, maintained by Hack-with-Github: 117,538 stars, 10,586 forks, and two tables of external links split between primary awesome-list repositories and standalone reference tools. It doesn't teach anything itself - every row is a one-line pointer to someone else's list, spanning Android security to prompt injection against AI systems, released under CC0-1.0.

3638117.5k10.6k
# android# awesome# bug-bounty
10.6kĐọc review

Thêm repo Security

O
OWASP/CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

6496032.8k4.6k
Python
# application-security# appsec# best-practices
4.6kĐọc review
P
projectdiscovery/nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

27010230.3k3.8k
Go
# attack-surface# cve-scanner# dast
3.8kĐọc review
O
ory/hydra

Internet-scale OpenID Certified™ OpenID Connect and OAuth2.1 provider that integrates with your user management through headless APIs. Solve OIDC/OAuth2 user cases over night. Consume as a service on Ory Network or self-host. Trusted by OpenAI and many others for scale and security. Written in Go.

3239417.5k1.6k
Go
# authorization# cloud# docker
1.6kĐọc review
S
snail007/goproxy

🔥 Proxy is a high performance HTTP(S) proxies, SOCKS5 proxies,WEBSOCKET, TCP, UDP proxy server implemented by golang. Now, it supports chain-style proxies,nat forwarding in different lan,TCP/UDP port forwarding, SSH forwarding.Proxy是golang实现的高性能http,https,websocket,tcp,socks5代理服务器,支持内网穿透,链式代理,通讯加密,智能HTTP,SOCKS5代理,黑白名单,限速,限流量,限连接数,跨平台,KCP支持,认证API。

214317.1k3.1k
Go
# dns-proxy# encryption-proxy# http
3.1kĐọc review
C
cryptomator/cryptomator

Cryptomator for Windows, macOS, and Linux: Secure client-side encryption for your cloud storage, ensuring privacy and control over your data.

8428315.8k1.5k
Java
# cloud-storage# crypto# cryptography
1.5kĐọc review
F
future-architect/vuls

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

1469012.2k1.2k
Go
# administrator# cybersecurity# freebsd
1.2kĐọc review
J
jason5ng32/MyIP

The best IP Toolbox. Check your IP address & geolocation, test IP for WebRTC and DNS IP leaks, run an IP quality check, browser fingerprint check, website availability check, network speed test, global latency test, MTR test, Whois search, and more.

10011.5k1.2k
JavaScript
# awesome# censorship# dns
1.2kĐọc review
1
1N3/Sn1per

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

36710.7k2.1k
Shell
# attack-surface# attack-surface-management# attacksurface
2.1kĐọc review
P
pennersr/django-allauth

Integrated set of Django applications addressing authentication, registration, account management as well as 3rd party (social) account authentication. 🔁 Mirror of https://codeberg.org/allauth/django-allauth/

806210.4k3.1k
Python
# accounts# authentication# django
3.1kĐọc review
W
wpscanteam/wpscan

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via [email protected]

7009.7k1.3k
Ruby
# hacking-tool# scan# scanner
1.3kĐọc review
O
OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

176429.7k1.7k
# application-security# appsec# best-practices
1.7kĐọc review
Y
yogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

951638.8k1.3k
HTML
# bug-bounty# bugbounty# hacking
1.3kĐọc review

Khám phá chủ đề khác