awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

9 Repos

Awesome GitHub RepositoriesEndpoint Security

Tools for hardening and monitoring specific operating systems.

Explore 9 awesome GitHub repositories matching part of an awesome list · Endpoint Security. Refine with filters or upvote what's useful.

Awesome Endpoint Security GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • orange-cyberdefense/goadAvatar von Orange-Cyberdefense

    Orange-Cyberdefense/GOAD

    7,464Auf GitHub ansehen↗

    GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including

    Configures workstations with restrictions like blocked LSASS stealing to emulate a hardened endpoint environment.

    PowerShellactive-directoryansibleinfrastructure-as-code
    Auf GitHub ansehen↗7,464
  • google/santaAvatar von google

    google/santa

    4,510Auf GitHub ansehen↗

    Santa ist ein binäres Autorisierungssystem für macOS, das entwickelt wurde, um zu kontrollieren und zu überwachen, welche Binärdateien basierend auf definierten Vertrauensregeln ausgeführt werden dürfen. Es fungiert als Software zur Anwendungs-Whitelisting, die die Ausführung nicht autorisierter Programme verhindert, indem sie diese gegen kryptografische Hashes und Signaturzertifikate prüft. Das System bietet Ausführungsüberwachung, indem es jedes Binärstart-Ereignis aufzeichnet, um einen sichtbaren Software-Ausführungspfad zu erstellen. Es ermöglicht zentralisiertes Audit-Logging, um erfolgreiche und abgelehnte Anwendungsstarts über mehrere Geräte hinweg zu verfolgen und die Compliance von Unternehmensgeräten durch synchronisierte Regeln und Logs sicherzustellen. Die Steuerung erfolgt über ein Regelsystem, das kryptografische Prüfsummen, digitale Signaturprüfung und Pfadabgleich mittels regulärer Ausdrücke nutzt. Das Framework beinhaltet eine Ausführungsabfangung auf Kernel-Ebene, um Binärdateien vor der Ausführung zu verifizieren, und unterhält eine lokale Datenbank zur Aufzeichnung von Aktivitäten und Audits.

    Manages binary allow-listing and deny-listing for macOS.

    Objective-C++
    Auf GitHub ansehen↗4,510
  • securitywithoutborders/hardentoolsAvatar von securitywithoutborders

    securitywithoutborders/hardentools

    3,093Auf GitHub ansehen↗

    Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.

    Disables risky features to harden Windows systems.

    Go
    Auf GitHub ansehen↗3,093
  • nsacyber/windows-secure-host-baselineAvatar von nsacyber

    nsacyber/Windows-Secure-Host-Baseline

    1,592Auf GitHub ansehen↗

    Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber

    Provides automated configuration and compliance checks for Windows.

    HTML
    Auf GitHub ansehen↗1,592
  • alichtman/strongholdAvatar von alichtman

    alichtman/stronghold

    1,190Auf GitHub ansehen↗

    Easily configure macOS security settings from the terminal.

    Configures macOS security settings via the command line.

    Pythoncommand-linecommand-line-toolhardening
    Auf GitHub ansehen↗1,190
  • apr4h/cobaltstrikescanAvatar von Apr4h

    Apr4h/CobaltStrikeScan

    921Auf GitHub ansehen↗

    Scan files or process memory for CobaltStrike beacons and parse their configuration

    Scans memory and files for malicious beacon signatures.

    C#
    Auf GitHub ansehen↗921
  • essandess/macos-fortressAvatar von essandess

    essandess/macOS-Fortress

    450Auf GitHub ansehen↗

    Firewall and Privatizing Proxy for Trackers, Attackers, Malware, Adware, and Spammers with Anti-Virus On-Demand and On-Access Scanning (PF, squid, privoxy, hphosts, dshield, emergingthreats, hostsfile, PAC file, clamav)

    Automates kernel and OS-level security configurations for macOS.

    Shell
    Auf GitHub ansehen↗450
  • linuz/sticky-keys-slayerAvatar von linuz

    linuz/Sticky-Keys-Slayer

    347Auf GitHub ansehen↗

    Scans for accessibility tools backdoors via RDP

    Scans for accessibility tool backdoors in Windows RDP sessions.

    Shell
    Auf GitHub ansehen↗347
  • sensepost/notrulerAvatar von sensepost

    sensepost/notruler

    96Auf GitHub ansehen↗

    The opposite of Ruler, provides blue teams with the ability to detect Ruler usage against Exchange.

    Detects malicious Exchange server rule and form modifications.

    Go
    Auf GitHub ansehen↗96
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Endpoint Security