awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

11 مستودعات

Awesome GitHub RepositoriesScan Contextualization

Provides credentials and focus areas to tailor vulnerability research.

Distinct from Vulnerability Scanning: Distinct from general vulnerability scanning: focuses on user-provided guidance and context.

Explore 11 awesome GitHub repositories matching security & cryptography · Scan Contextualization. Refine with filters or upvote what's useful.

Awesome Scan Contextualization GitHub Repositories

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • usestrix/strixالصورة الرمزية لـ usestrix

    usestrix/strix

    20,138عرض على GitHub↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Provides context, credentials, and focus areas to the analysis engine to tailor the scope of vulnerability research.

    Pythonagentsartificial-intelligencecybersecurity
    عرض على GitHub↗20,138
  • zaproxy/zaproxyالصورة الرمزية لـ zaproxy

    zaproxy/zaproxy

    15,293عرض على GitHub↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Implements an active scanning engine that sends malicious payloads to identify web vulnerabilities.

    Java
    عرض على GitHub↗15,293
  • alfresco/prowlerالصورة الرمزية لـ Alfresco

    Alfresco/prowler

    14,005عرض على GitHub↗

    Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove

    Ships a modular scanning engine that executes a library of security checks to identify multi-cloud misconfigurations.

    Python
    عرض على GitHub↗14,005
  • drwetter/testssl.shالصورة الرمزية لـ drwetter

    drwetter/testssl.sh

    9,091عرض على GitHub↗

    testssl.sh is a suite of diagnostic tools and a network security auditor used to scan network ports for supported encryption protocols, ciphers, and vulnerabilities in TLS and SSL configurations. It functions as a security scanner that evaluates the cryptographic strength of a server by testing all available cipher suites. The tool analyzes server encryption strength and identifies security vulnerabilities or weak settings through TLS and SSL security auditing. It verifies that encryption is properly implemented on specific network ports and evaluates whether only strong and modern encryption

    Implements a modular engine to execute sequential security checks for protocol and vulnerability detection.

    Shell
    عرض على GitHub↗9,091
  • google/tsunami-security-scannerالصورة الرمزية لـ google

    google/tsunami-security-scanner

    8,584عرض على GitHub↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    Utilizes a modular engine that executes interchangeable detection plugins for vulnerability identification.

    Java
    عرض على GitHub↗8,584
  • owasp/nettackerالصورة الرمزية لـ OWASP

    OWASP/Nettacker

    5,258عرض على GitHub↗

    Nettacker هو إطار عمل لاختبار الاختراق المؤتمت مصمم لتنسيق الاستطلاع، وفحص المنافذ، واكتشاف الثغرات الأمنية. يعمل كأداة لاستطلاع الشبكة وماسح للثغرات الأمنية يقوم بتحديد المنافذ المفتوحة، وبصمات الخدمات، وفحص الأنظمة مقابل قواعد بيانات الثغرات الأمنية المعروفة. يتميز إطار العمل بدمج زاحف لتطبيقات الويب لاكتشاف المسارات المخفية عبر الـ fuzzing مع نظام لإدارة الثغرات الأمنية يحتفظ بنتائج الفحص في قاعدة بيانات لتتبع التقييمات التاريخية. كما يتضمن قدرات متخصصة لتعداد النطاقات الفرعية، وهجمات القوة الغاشمة (brute forcing) على بيانات الاعتماد، والقدرة على توجيه حركة المرور عبر وكلاء (proxies) لإخفاء الهوية. يغطي النظام نطاقاً واسعاً من القدرات الأمنية، بما في ذلك اكتشاف أصول الشبكة، وتدقيق الخدمات متعددة البروتوكولات، وتدقيق التكوين. ويدعم الفحص متعدد الأهداف عبر نطاقات IP وكتل CIDR، ويوفر أدوات لتوليد تقارير أمنية بتنسيقات متعددة. التحكم البرمجي متاح عبر واجهة REST، مما يسمح بدمج إطار العمل في خطوط أنابيب الأمان وسير عمل الأتمتة.

    Implements a network scanning tool that identifies active devices and services across a target network.

    Pythonautomationbruteforcecve
    عرض على GitHub↗5,258
  • credittone/hookerالصورة الرمزية لـ CreditTone

    CreditTone/hooker

    5,195عرض على GitHub↗

    Hooker هي مجموعة أدوات للتحليل الديناميكي، وتحليل الذاكرة، وإلغاء التعتيم لتطبيقات Android. تعمل كإطار عمل للهندسة العكسية يستخدم Frida لحقن نصوص برمجية في العمليات الجارية، ومراقبة الاستدعاءات الأصلية، واستخراج ملفات DEX القابلة للتنفيذ. يوفر المشروع أدوات متخصصة لتجاوز ضوابط الأمان، بما في ذلك أدوات لتعطيل التحقق من شهادة SSL وتثبيت BoringSSL لتمكين اعتراض حركة مرور HTTPS. يتضمن إمكانيات لاكتشاف حزم التطبيقات، واستخراج مفاتيح التشفير عن طريق ربط خوارزميات التشفير، والالتفاف على فحوصات بيئة الجذر (root) أو التصحيح. يغطي إطار العمل مجموعة واسعة من إمكانيات التحليل، بما في ذلك مسح الذاكرة لاكتشاف المكونات النشطة، وتكوين وكيل SOCKS5 لتوجيه حركة مرور الشبكة، وتحليل تفاعل واجهة المستخدم. كما يدعم جمع بصمات الأجهزة وتصحيح أخطاء WebViews المضمنة.

    A toolkit for scanning application memory to detect active services and map component addresses.

    JavaScriptandroidapkboringssl
    عرض على GitHub↗5,195
  • aquasecurity/kube-hunterالصورة الرمزية لـ aquasecurity

    aquasecurity/kube-hunter

    5,064عرض على GitHub↗

    Kube-hunter هو ماسح أمني وصياد ثغرات لمجموعات Kubernetes. يعمل كأداة اختراق سحابية أصلية مصممة لتحديد نقاط الضعف الأمنية، وتكوينات البنية التحتية الخاطئة، والفجوات القابلة للاستغلال من خلال محاكاة تقنيات المهاجم. تتميز الأداة بمحرك مسح مزدوج الوضع ينفذ كلاً من تحقيقات خارجية عن بُعد ومسح شبكة داخلي. يتميز بانتحال الهوية القائم على الهوية، مما يسمح له باستخدام رموز حساب الخدمة وهويات الحاوية (Pod) لمحاكاة الوصول الأمني من أدوار مجموعة محددة وتحديد نصف قطر الانفجار المحتمل لاختراق الحاوية. يغطي المشروع مساحة واسعة من قدرات التقييم الأمني، بما في ذلك مسح ثغرات المجموعة، ورسم خرائط طوبولوجيا الشبكة الداخلية، والتحقق من الامتثال. يمكنه اكتشاف الأسرار المكشوفة، وتحليل قوالب البنية التحتية بحثاً عن تكوينات خاطئة، وإجراء محاولات استغلال نشطة للتحقق من أن الثغرات المكتشفة قابلة للاستفادة منها. يتم حزم التطبيق كملف تنفيذي مستقل لإزالة تبعيات وقت التشغيل أثناء النشر.

    Implements an active scanning engine that executes both remote probes and internal network scans to identify vulnerabilities.

    Python
    عرض على GitHub↗5,064
  • hahwul/dalfoxالصورة الرمزية لـ hahwul

    hahwul/dalfox

    4,846عرض على GitHub↗

    Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t

    Injects cookies or custom headers to scan protected or stateful application areas.

    Gobugbountybugbounty-toolcicd-pipeline
    عرض على GitHub↗4,846
  • 0x727/shuize_0x727الصورة الرمزية لـ 0x727

    0x727/ShuiZe_0x727

    4,014عرض على GitHub↗

    ShuiZe_0x727 is an open-source intelligence gathering framework and attack surface management tool. It functions as an asset discovery engine and cyber intelligence aggregator designed to identify internet-facing assets, map network infrastructure, and visualize total network exposure. The project integrates vulnerability scanning and sensitive data leak detection to identify security weaknesses and unauthorized access points. It employs a combination of network space API queries, certificate log analysis, and public repository scanning to extract leaked credentials, API keys, and internal ad

    Employs a modular scanning engine to execute isolated vulnerability tests and port scanning routines.

    Python
    عرض على GitHub↗4,014
  • aquasecurity/cloudsploitالصورة الرمزية لـ aquasecurity

    aquasecurity/cloudsploit

    3,705عرض على GitHub↗

    Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource

    Uses a modular engine to execute a library of security check plugins across cloud environments.

    JavaScriptalibabaaquaaws
    عرض على GitHub↗3,705
  1. Home
  2. Security & Cryptography
  3. Vulnerability Scanning
  4. Scan Contextualization

استكشف الوسوم الفرعية

  • Active Scanning Engines3 وسوم فرعيةComponents that actively send payloads to endpoints to identify vulnerabilities through server behavior. **Distinct from Scan Contextualization:** Distinct from Scan Contextualization: focuses on the execution engine and payload delivery rather than the targeting context.