
SentryPeer
Distributed SIP honeypot that detects and shares fraud data on VoIP attacks. Collects bad actor IPs and phone numbers via peer-to-peer network, with…

Distributed SIP honeypot that detects and shares fraud data on VoIP attacks. Collects bad actor IPs and phone numbers via peer-to-peer network, with…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

CVE-2025-55182 and CVE-2025-66478

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

An open-source framework for verifiably private AI inference

A reverse proxy like nginx, built on pingora, simple and efficient.

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

Zero-knowledge privacy platform for confidential API key management, encrypted vault, and secure chat. Built on Oasis Sapphire TEEs

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Frida-based runtime API monitor for Android apps that logs invoked APIs, parameters, return values, and call origins across predefined or custom…

ZTE SmartLife security findings leading to account takeover: 100K+ Google Play downloads and CVE-2026-86552 through CVE-2026-86555.

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.