
noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

TrustedRouter.com repo for secure LLM proxying

PHP 8.4+ security library (mirror)

Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

An open source threat modeling tool from OWASP

A reverse proxy like nginx, built on pingora, simple and efficient.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Automatic SQL injection and database takeover tool

Traccar GPS Tracking System

Powerful protection for AI agents - Open-source security and cost tracking for AI applications

A next-generation crawling and spidering framework.

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…