6 dépôts
Using signature-based matching to identify specific vulnerabilities or software patterns across assets.
Distinct from Vulnerability Scanning: Focuses on YARA-style pattern matching across discovered assets rather than general image or package scanning
Explore 6 awesome GitHub repositories matching security & cryptography · Pattern-Based Detection. Refine with filters or upvote what's useful.
This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions as a containerized security scanner designed to map public-facing infrastructure, perform subdomain enumeration, and automate the gathering of open-source intelligence. The system employs a recursive discovery engine to iteratively explore target infrastructure, utilizing a plugin-based module architecture to extend scanning capabilities. It integrates third-party APIs for data enrichment and applies YARA rules across discovered assets to identify specific vulnerability patte
Applies YARA rules to scan the discovered attack surface for specific files, patterns, or known software vulnerabilities.
MySQLTuner-perl is a diagnostic utility and Perl script designed for optimizing database configurations, auditing security, monitoring resources, and analyzing performance. It functions as a configuration optimizer and performance tuning tool that analyzes server variables to provide specific recommendations for increasing system stability and speed. The tool acts as a database auditor by evaluating security settings, SSL configurations, and schema integrity to identify vulnerabilities. It also serves as a resource monitor that forecasts capacity needs and calculates health scores based on di
Identifies the underlying hosting environment by scanning system metadata and network signatures for cloud provider patterns.
testssl.sh is a suite of diagnostic tools and a network security auditor used to scan network ports for supported encryption protocols, ciphers, and vulnerabilities in TLS and SSL configurations. It functions as a security scanner that evaluates the cryptographic strength of a server by testing all available cipher suites. The tool analyzes server encryption strength and identifies security vulnerabilities or weak settings through TLS and SSL security auditing. It verifies that encryption is properly implemented on specific network ports and evaluates whether only strong and modern encryption
Uses signature-based pattern matching to identify specific SSL and TLS vulnerabilities in server responses.
Canta est un gestionnaire d'applications système sans root et un outil de suppression de bloatware pour Android. Il identifie et supprime les logiciels système non essentiels en tirant parti des services système privilégiés. L'outil utilise une liste organisée de paquets pouvant être supprimés sans risque pour identifier les bloatwares et éviter l'instabilité du système. Il exécute ces suppressions sans nécessiter un accès root complet à l'appareil en utilisant le service Shizuku pour l'exécution de commandes privilégiées. Le projet offre des capacités de désinstallation d'applications sans root, de désactivation non destructive d'applications et d'optimisation système via le filtrage de paquets et l'exécution de processus via ADB.
Provides a system to identify pre-installed bloatware by matching installed packages against curated safe-to-delete lists.
RyTuneX is a utility suite designed for managing operating system features, removing bloatware, and controlling data privacy settings. It functions as a system optimizer and debloater that allows users to uninstall preinstalled applications and tune system configurations to improve performance and reliability. The project includes a privacy manager to disable telemetry and block data collection tracking. It provides a dashboard for modifying system behaviors and hardware specifications through a simplified interface, including toggle switches for native operating system features. The suite c
Identifies preinstalled applications by matching package names and paths against a known bloatware database.
nodejsscan is a static analysis security tool and vulnerability detection engine designed to scan Node.js source code for security flaws and common coding vulnerabilities. It functions as a static application security testing tool that analyzes code without executing the program. The tool operates as a security linter that can be integrated into continuous integration pipelines to block insecure code from merging into main branches. It automates the auditing process through rule-based detection and pattern-based static analysis. The project provides capabilities for vulnerability alert autom
Matches specific code patterns against a library of security flaws to flag risks.