45 repositorios
Infrastructure and platforms for testing security tools and attack scenarios.
Explore 45 awesome GitHub repositories matching part of an awesome list · Security Lab Environments. Refine with filters or upvote what's useful.
Ansible is an agentless infrastructure automation engine designed to manage remote servers and network devices. It functions as a cross-platform orchestration tool that coordinates system updates, software installations, and service configurations from a centralized management workstation. By utilizing a declarative approach, it allows users to define desired system states through human-readable configuration files, ensuring consistency across distributed environments. The platform operates by establishing secure shell connections to target nodes, eliminating the need for persistent agent sof
Automation tool for configuring and managing security infrastructure.
Semgrep is a static analysis security testing tool designed to identify vulnerabilities and logic errors by matching source code against declarative patterns. It functions as an automated scanner that integrates into development workflows to detect insecure code patterns and enforce coding standards before deployment. The engine utilizes a language-agnostic intermediate representation and a modular parser architecture to normalize diverse programming languages into a unified format. This allows for consistent rule execution across different codebases, enabling users to perform custom structur
Static analysis tool for finding vulnerabilities in source code.
Ecapture is a suite of specialized auditing tools designed to capture plaintext database queries, log executed shell commands, forward packet captures, and decrypt TLS traffic. The system extracts plaintext content from encrypted communications and TLS master secrets without requiring CA certificates. It further monitors data interactions by capturing SQL queries from database instances and recording commands from shell environments for host-level auditing. The toolset includes capabilities for network traffic analysis, exporting captured data to pcapng files, and forwarding events to extern
Tool for capturing encrypted traffic using eBPF.
Lynis is an automated security auditing and system hardening framework designed for UNIX-based operating systems. It functions as a command-line utility that inspects local system configurations to identify security vulnerabilities, configuration weaknesses, and compliance gaps. By executing a series of modular tests, the tool generates actionable reports and remediation suggestions to assist in strengthening system defenses. The project distinguishes itself through a highly modular architecture that relies on shell-script-based execution and native system inspection. Users can define custom
Security auditing and hardening tool for Unix-based systems.
Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito
Unified XDR and SIEM platform for threat detection and response.
Xpipe is a remote infrastructure management tool and cross-platform terminal orchestrator. It provides a centralized desktop interface for managing remote server connections, shell sessions, and secure tunneling. The system functions as a remote application gateway, streaming graphical applications to a local desktop via RDP, VNC, or X11. It also implements a Model Context Protocol server, which exposes server infrastructure and remote command execution capabilities to external AI agents. The tool covers several operational areas, including hierarchical connection management, remote file sys
Tool for managing and connecting to remote systems.
Flare-VM es un entorno de análisis de malware para Windows que consiste en scripts de instalación que automatizan el aprovisionamiento de una máquina virtual. Proporciona un conjunto integral de herramientas de ingeniería inversa, incluyendo descompiladores y depuradores, junto con las configuraciones del sistema y variables de entorno necesarias para la investigación de seguridad. El proyecto funciona como un orquestador de imágenes de máquinas virtuales, permitiendo la creación, gestión y exportación automatizadas de dispositivos de análisis especializados. Cuenta con selección de herramientas basada en configuración y la capacidad de extender la lógica de instalación mediante modificaciones personalizadas del registro y definiciones de diseño del sistema. El sistema incluye capacidades para la configuración de red aislada para evitar la comunicación externa mediante el modo host-only. También gestiona el ciclo de vida completo de los estados de análisis mediante la gestión de estados basada en instantáneas, incluida la capacidad de limpiar o exportar instantáneas como archivos de dispositivo verificados.
Windows-based distribution for malware analysis and reverse engineering.
OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide
Platform for managing and sharing cyber threat intelligence.
Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o
Malicious traffic detection system using public blacklists.
GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including
Automated lab environment for testing Active Directory attacks.
MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish
Platform for sharing indicators of compromise and threat intelligence.
.. SPDX-FileCopyrightText: 2014 Upi Tamminen .. SPDX-FileCopyrightText: 2014-2025 Michel Oosterhof .. .. SPDX-License-Identifier: BSD-3-Clause
Medium-to-high interaction SSH and Telnet honeypot.
Cuckoo is an open-source automated malware analysis system that executes suspicious files inside isolated virtual machines and produces structured behavioral reports. The platform captures system calls, file operations, and network activity during execution, compiling them into comprehensive analysis documents for programmatic consumption. The system operates through a modular analysis pipeline that processes behavioral data, applying YARA signature patterns against captured artifacts to identify known malware families. Each analysis run starts from a clean virtual machine snapshot to ensure
Automated malware analysis system for observing malicious behavior.
Katoolin es un gestor de repositorios de software de Debian y automatizador de conjuntos de herramientas de seguridad. Funciona como un script para automatizar la adición de repositorios y la instalación de herramientas de seguridad de Kali Linux en otros sistemas basados en Debian. El proyecto se centra en automatizar el despliegue de software de pruebas de penetración y forense. Proporciona un método para gestionar fuentes de software de terceros y aprovisionar laboratorios de seguridad con herramientas para pruebas de red y de sistema sin requerir una instalación completa del sistema operativo. La herramienta incluye una interfaz de línea de comandos interactiva para navegar por las categorías de herramientas y gestionar paquetes de software a través de un proceso impulsado por shell. Organiza el software en agrupaciones modulares para permitir la instalación de subconjuntos específicos o suites completas de herramientas.
Quickly configures Linux environments with necessary software for ethical hacking and security research.
Security Onion es una plataforma de gestión de eventos e información de seguridad (SIEM) y una suite de monitoreo de seguridad de red. Funciona como un sistema de detección de intrusos y una herramienta de análisis de tráfico de red diseñada para identificar actividad maliciosa e intrusiones mediante detección basada en firmas y monitoreo de hosts. La plataforma integra un sistema de gestión de casos de seguridad para organizar investigaciones, rastreando detecciones y agrupando eventos de seguridad relacionados. Ofrece capacidades para captura completa de paquetes, extracción de metadatos de red y recolección e indexación de registros de seguridad de diversas fuentes. El sistema cubre un amplio rango de operaciones de seguridad, incluyendo investigación de incidentes, flujos de trabajo de threat hunting y agregación de logs. Utiliza una consola web unificada para analizar eventos y alertas, e incorpora inteligencia artificial para asistir en la investigación de datos de seguridad.
Linux distribution for intrusion detection and enterprise security monitoring.
Pikachu es una plataforma de entrenamiento en seguridad web y sandbox de aplicaciones web vulnerables. Proporciona un entorno de laboratorio en contenedores diseñado para practicar pruebas de penetración e identificar fallas de seguridad comunes. El proyecto sirve como laboratorio de práctica para el OWASP Top 10, ofreciendo una suite de simulación para riesgos críticos. Incluye escenarios específicos para practicar la explotación de inyección SQL, cross-site scripting (XSS), ejecución remota de código y control de acceso roto. El entorno cubre una amplia gama de simulaciones de pruebas de seguridad, incluyendo directory traversal, server-side request forgery (SSRF), carga de archivos insegura y ataques de entidades externas XML (XXE). También cuenta con un backend administrativo para gestionar simulaciones de phishing y monitorear payloads de sesión capturados. La plataforma completa se despliega mediante una imagen en contenedores que inicializa automáticamente el esquema de la base de datos y puebla el entorno con datos de prueba.
Provides an isolated testing setup deployed via containers for a consistent security research workspace.
Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho
Runtime security and forensics tool using eBPF.
Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices. The project distinguishes itself through a comprehensive execution control system, featuring a manager for Windows Application Control and a kernel protection suite. It implements strict trust models, including kernel-mode driver whitelisting, signed policy implementation on the EFI partition, and code inte
Script for hardening Windows system configurations.
Malware Configuration And Payload Extraction
Automated malware analysis platform with advanced reporting capabilities.
OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network. The system uses deception technology to mimic various server protocols, luring attackers into revealing their presence and activity. When a simulated service is accessed, it acts as an intrusion alerting gateway, transmitting notifications via email or webhooks. The project covers internal network monitoring and intrusion source tracking to identify the
Deception tool for detecting unauthorized network activity.