Awesome Rust Security
Curated list of awesome projects and resources related to Rust and computer security
Table of Contents
Web and Cloud Security
Pentesting
- sn0int - OSINT framework and package manager
- sniffglue - secure multithreaded packet sniffer
- badtouch - scriptable network authentication cracker
- rshijack - TCP connection hijacker
- feroxbuster - fast, simple and recursive content discovery tool
- rustbuster - web fuzzer and content discovery tool
- rustscan - The Modern Port Scanner
- kepler - NIST-based CVE lookup store and API powered by Rust.
- phaser - Automated attack surface mapper and vulnerability scanner
- pdfrip - Fast PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks.
- chromepass - Chromepass - Hacking Chrome Saved Passwords
Authorization & Authentication Frameworks
- biscuit - delegated, decentralized, capabilities based authorization token
- paseto.rs - PASETO Rust implementation
- webauthn.rs - WebAuthn implementation in Rust
- aliri - JWT authenticaiton and OAuth2 scope authorization implementations for many web frameworks
- OpenSK - open-source implementation for security keys written in Rust
- dacquiri - Attributed based access control (ABAC) framework with compile-time enforcement
Cloud and Infrastructure
- firecracker - secure and fast microVMs for serverless computing
- boringtun - CloudFlare's Rust implementation of WireGuard
- innernet - private network based on WireGuard
- vaultwarden - unofficial BitWarden implementation in Rust
Software Supply Chain
Secure Frameworks
Vulnerability Assessment
Static Code Auditing
- RustSec - organization supporting vulnerability disclosure for Rust packages, audit Cargo.lock files for dependencies
- cargo-geiger - detect usage of unsafe Rust
- siderophile - find ideal fuzz targets in a Rust codebase
- cargo-crev - cryptographically verifiable code review for cargo
- arch-audit - audit installed Arch packages for vulnerabilities
- ripgrep - recursively search directories with regexes
- weggli - fast and robust semantic search tool for C and C++ codebases
- noseyparker - command-line program that finds secrets and sensitive information in textual data and Git history.
- L3X - AI-driven Static Analyzer
Fuzzing
- rust-fuzz - organization implementing cargo plugins for AFL, libFuzzer, and honggfuzz
- LibAFL - slot fuzzers together in Rust
- fuzzcheck.rs - structure-aware, in-process, coverage-guided, evolutionary fuzzing engine for Rust functions.
- onefuzz - self-hosted Fuzzing-As-A-Service platform
- lain - fuzzer framework implemented in Rust
- fzero - fast grammar-based fuzz generator implementation
- nautilus - grammar-based feedback fuzzer from RUB's Systems Security Lab
- sidefuzz - fuzzer for side-channel vulnerabilities
- arbitrary - trait for generating structured input from raw bytes, helpful for structure-aware fuzzing
- rust-san - sanitizers for Rust code
- lidiffuzz - memory allocator drop-in to test for uninitialized memory reads
- rewind - Snapshot-based coverage-guided Windows kernel fuzzer
- hyperpom - AArch64 fuzzer based on the Apple Silicon hypervisor
- icicle-emu - Fuzzing-specific multi-architecture emulation framework
Binary Analysis & Reversing
- goblin - binary parsing crate for Rust
- unicorn.rs - Rust bindings to the Unicorn framework
- cargo-call-stack - whole program stack analysis
- xori - disassembly library for PE32, 32+ and shellcode
- rd - record/replay debugger implemented in Rust
- binsec - Swiss Army Knife for Binary (In)Security
- radeco - Radare2-based decompiler and symbol executor
- falcon - Binary Analysis Framework in Rust
- mesos - binary coverage tool without modification for Windows
- guerilla - monkey patching Rust functions
- ropr - blazing fast™ multithreaded ROP Gadget finder
- pwninit - automate starting binary exploit challenges
- binaryninja-rs - Binary Ninja API support for Rust
Property-Based Testing