
TrojanSourceFinder
🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)

🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)

Open Source Cloud Native Application Protection Platform (CNAPP)

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Vulmap Online Local Vulnerability Scanners Project

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

DEPRECATED - A prototype SSH configuration and policy scanner (Blog: https://mozilla.github.io/ssh_scan/)

Module-based web vulnerability scanner and bug bounty automation framework with built-in XSS, SSTI, SSRF, and Firebase detection engines. Designed to…

JF⚡can - Super fast port scanning & service discovery using Masscan and Nmap. Scan large networks with Masscan and use Nmap's scripting abilities to…

A PowerShell script that automates the security assessment of Microsoft 365 environments.