45 dépôts
Infrastructure and platforms for testing security tools and attack scenarios.
Explore 45 awesome GitHub repositories matching part of an awesome list · Security Lab Environments. Refine with filters or upvote what's useful.
Ansible is an agentless infrastructure automation engine designed to manage remote servers and network devices. It functions as a cross-platform orchestration tool that coordinates system updates, software installations, and service configurations from a centralized management workstation. By utilizing a declarative approach, it allows users to define desired system states through human-readable configuration files, ensuring consistency across distributed environments. The platform operates by establishing secure shell connections to target nodes, eliminating the need for persistent agent sof
Automation tool for configuring and managing security infrastructure.
Semgrep is a static analysis security testing tool designed to identify vulnerabilities and logic errors by matching source code against declarative patterns. It functions as an automated scanner that integrates into development workflows to detect insecure code patterns and enforce coding standards before deployment. The engine utilizes a language-agnostic intermediate representation and a modular parser architecture to normalize diverse programming languages into a unified format. This allows for consistent rule execution across different codebases, enabling users to perform custom structur
Static analysis tool for finding vulnerabilities in source code.
Ecapture is a suite of specialized auditing tools designed to capture plaintext database queries, log executed shell commands, forward packet captures, and decrypt TLS traffic. The system extracts plaintext content from encrypted communications and TLS master secrets without requiring CA certificates. It further monitors data interactions by capturing SQL queries from database instances and recording commands from shell environments for host-level auditing. The toolset includes capabilities for network traffic analysis, exporting captured data to pcapng files, and forwarding events to extern
Tool for capturing encrypted traffic using eBPF.
Lynis is an automated security auditing and system hardening framework designed for UNIX-based operating systems. It functions as a command-line utility that inspects local system configurations to identify security vulnerabilities, configuration weaknesses, and compliance gaps. By executing a series of modular tests, the tool generates actionable reports and remediation suggestions to assist in strengthening system defenses. The project distinguishes itself through a highly modular architecture that relies on shell-script-based execution and native system inspection. Users can define custom
Security auditing and hardening tool for Unix-based systems.
Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito
Unified XDR and SIEM platform for threat detection and response.
Xpipe is a remote infrastructure management tool and cross-platform terminal orchestrator. It provides a centralized desktop interface for managing remote server connections, shell sessions, and secure tunneling. The system functions as a remote application gateway, streaming graphical applications to a local desktop via RDP, VNC, or X11. It also implements a Model Context Protocol server, which exposes server infrastructure and remote command execution capabilities to external AI agents. The tool covers several operational areas, including hierarchical connection management, remote file sys
Tool for managing and connecting to remote systems.
Flare-VM est un environnement d'analyse de logiciels malveillants Windows composé de scripts d'installation qui automatisent le provisionnement d'une machine virtuelle. Il fournit une suite complète d'outils de rétro-ingénierie, incluant des décompilateurs et des débogueurs, ainsi que les configurations système et variables d'environnement nécessaires à la recherche en sécurité. Le projet fonctionne comme un orchestrateur d'images de machine virtuelle, permettant la création, la gestion et l'exportation automatisées d'appliances d'analyse spécialisées. Il propose une sélection d'outils pilotée par la configuration et la possibilité d'étendre la logique d'installation via des modifications de registre personnalisées et des définitions de mise en page système. Le système inclut des capacités de configuration réseau isolée pour empêcher toute communication externe via le mode hôte uniquement. Il gère également le cycle de vie complet des états d'analyse via une gestion d'état basée sur des snapshots, incluant la possibilité de nettoyer ou d'exporter des snapshots en tant que fichiers d'appliance vérifiés.
Windows-based distribution for malware analysis and reverse engineering.
OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide
Platform for managing and sharing cyber threat intelligence.
Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o
Malicious traffic detection system using public blacklists.
GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including
Automated lab environment for testing Active Directory attacks.
MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish
Platform for sharing indicators of compromise and threat intelligence.
.. SPDX-FileCopyrightText: 2014 Upi Tamminen .. SPDX-FileCopyrightText: 2014-2025 Michel Oosterhof .. .. SPDX-License-Identifier: BSD-3-Clause
Medium-to-high interaction SSH and Telnet honeypot.
Cuckoo is an open-source automated malware analysis system that executes suspicious files inside isolated virtual machines and produces structured behavioral reports. The platform captures system calls, file operations, and network activity during execution, compiling them into comprehensive analysis documents for programmatic consumption. The system operates through a modular analysis pipeline that processes behavioral data, applying YARA signature patterns against captured artifacts to identify known malware families. Each analysis run starts from a clean virtual machine snapshot to ensure
Automated malware analysis system for observing malicious behavior.
Katoolin est un gestionnaire de dépôts de logiciels Debian et un automatiseur de suite d'outils de sécurité. Il fonctionne comme un script pour automatiser l'ajout de dépôts et l'installation d'outils de sécurité de Kali Linux sur d'autres systèmes basés sur Debian. Le projet se concentre sur l'automatisation du déploiement de logiciels de test d'intrusion et de criminalistique. Il fournit une méthode pour gérer les sources logicielles tierces et approvisionner des laboratoires de sécurité avec des outils pour les tests réseau et système sans nécessiter une installation complète du système d'exploitation. L'outil inclut une interface en ligne de commande interactive pour naviguer dans les catégories d'outils et gérer les paquets logiciels via un processus piloté par shell. Il organise les logiciels en regroupements modulaires pour permettre l'installation de sous-ensembles spécifiques ou de suites complètes d'outils.
Quickly configures Linux environments with necessary software for ethical hacking and security research.
Security Onion est une plateforme de gestion des informations et des événements de sécurité (SIEM) ainsi qu'une suite de surveillance de la sécurité réseau. Elle fonctionne comme un système de détection d'intrusions et un outil d'analyse du trafic réseau conçu pour identifier les activités malveillantes et les intrusions via une détection basée sur les signatures et une surveillance basée sur les hôtes. La plateforme intègre un système de gestion des incidents de sécurité pour organiser les enquêtes en suivant les détections et en regroupant les événements de sécurité associés. Elle offre des capacités de capture complète de paquets, d'extraction de métadonnées réseau, ainsi que de collecte et d'indexation de journaux de sécurité provenant de sources diverses. Le système couvre un large éventail d'opérations de sécurité, notamment l'investigation d'incidents, les flux de travail de threat hunting et l'agrégation de journaux. Il utilise une console web unifiée pour analyser les événements et les alertes, et intègre l'intelligence artificielle pour assister l'investigation des données de sécurité.
Linux distribution for intrusion detection and enterprise security monitoring.
Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab environment designed for practicing penetration testing and identifying common security flaws. The project serves as an OWASP Top 10 practice lab, offering a simulation suite for critical risks. It includes specific scenarios for practicing the exploitation of SQL injection, cross-site scripting, remote code execution, and broken access control. The environment covers a broad range of security testing simulations, including directory traversal, server-side request forgery, unsa
Provides an isolated testing setup deployed via containers for a consistent security research workspace.
Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho
Runtime security and forensics tool using eBPF.
Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices. The project distinguishes itself through a comprehensive execution control system, featuring a manager for Windows Application Control and a kernel protection suite. It implements strict trust models, including kernel-mode driver whitelisting, signed policy implementation on the EFI partition, and code inte
Script for hardening Windows system configurations.
Malware Configuration And Payload Extraction
Automated malware analysis platform with advanced reporting capabilities.
OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network. The system uses deception technology to mimic various server protocols, luring attackers into revealing their presence and activity. When a simulated service is accessed, it acts as an intrusion alerting gateway, transmitting notifications via email or webhooks. The project covers internal network monitoring and intrusion source tracking to identify the
Deception tool for detecting unauthorized network activity.