12 रिपॉजिटरी
Pluggable architecture for adding custom security tests and vulnerability probes.
Distinct from Server Plugins and Extensions: None of the candidates describe a plugin system specifically for security scanning logic.
Explore 12 awesome GitHub repositories matching security & cryptography · Custom Security Scan Extensions. Refine with filters or upvote what's useful.
Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove
Offers a pluggable architecture and SDK for adding custom security tests and vulnerability probes.
Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast
Offers a pluggable architecture and SDK for adding custom security tests and vulnerability probes.
Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a reconnaissance engine designed to identify insecure server options, outdated software, and common vulnerabilities by analyzing HTTP responses. The project differentiates itself through capabilities for intrusion detection evasion and web server fingerprinting. It uses request-level encoding and timing spacers to bypass security filters and employs signature-based identification to determine specific server software versions and misconfigurations. The scanner covers broad capability are
Provides an extensibility system for adding custom tests and plugins to detect specific vulnerabilities.
Garak is an AI model evaluation tool and vulnerability scanner designed for red teaming large language models and auditing the security of retrieval-augmented generation pipelines. It identifies behavioral weaknesses, such as jailbreaks, hallucinations, and data leakage, by simulating adversarial attacks and executing automated testing vectors. The framework utilizes an adaptive probing loop where prompts can react to previous model behavior and be modified in flight via middleware. To ensure consistent analysis, it employs a provider-agnostic interface to interact with various model APIs and
Features a plugin-based architecture for adding custom probes, detectors, and testing vectors.
tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect misconfigurations and compliance violations in Terraform and cloud infrastructure definitions before deployment. It functions as a cloud security policy engine that identifies vulnerabilities across multiple cloud platforms. The tool provides capabilities for cloud compliance auditing and scanning of Cloud Development Kit code. It supports custom security policy enforcement and allows for the definition of organization-specific security requirements. The scanner includes features
Supports the definition of custom security policies and tailored checks to meet organizational requirements.
Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings from multiple scanners into a single dashboard. It utilizes a relational security database to catalog hosts, services, and security flaws, enabling users to track remediation and analyze organizational risk. The platform distinguishes itself through a plugin-based system that normalizes diverse security tool outputs into a unified data model. It supports deep integration with a wide array of scanners and CLI tools, intercepting shell command output or parsing report files to ag
Provides a pluggable architecture to include custom security tools and specialized executor scripts for scanning.
यह प्रोजेक्ट बड़े भाषा मॉडल (LLM) एजेंटों का उपयोग करके सुरक्षा कमजोरियों की स्वायत्त खोज और सुधार के लिए एक फ्रेमवर्क है। यह एक सुरक्षा अनुसंधान पाइपलाइन के रूप में कार्य करता है जो पुनरुत्पादक सॉफ्टवेयर बग्स की पहचान करने के लिए टोही, क्रैश डिस्कवरी और एक्सप्लॉइटेबिलिटी विश्लेषण की प्रक्रिया को स्वचालित करती है। यह सिस्टम एक कंटेनरीकृत एजेंट सैंडबॉक्स का उपयोग करके खुद को अलग करता है जो होस्ट कॉम्प्रोमाइज़ को रोकने के लिए नेटवर्क एग्रेस और फाइल सिस्टम एक्सेस को प्रतिबंधित करता है। यह एक विशेष पैच जनरेशन और वैलिडेशन लूप को नियोजित करता है, जिसमें एडवरसैरियल री-अटैक टेस्टिंग शामिल है जहाँ एक नया एजेंट सुधार की प्रभावशीलता सुनिश्चित करने के लिए नए इनपुट के साथ प्रस्तावित फिक्स को बायपास करने का प्रयास करता है। यह फ्रेमवर्क स्टेटिक भेद्यता विश्लेषण, अटैक सरफेस पार्टिशनिंग और थ्रेट मॉडल निर्माण सहित सुरक्षा क्षमताओं की एक विस्तृत श्रृंखला को कवर करता है। यह क्रैश सिग्नेचर क्लस्टरिंग और डिडुप्लीकेशन के माध्यम से भेद्यता ट्राइएज के लिए टूल्स प्रदान करता है, साथ ही कोडबेस में व्यवस्थित सुधार लागू करने के लिए बड़े पैमाने पर कोड माइग्रेशन निष्पादित करने की क्षमता भी प्रदान करता है।
Provides a pluggable architecture to customize build processes and success signals for different languages or vulnerability classes.
w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing
Features a modular system for tuning and enabling specific security test plugins to customize scans.
This project is a comprehensive Android reverse engineering suite that functions as a decompiler, bytecode deobfuscator, and malware analysis tool. It is designed to convert APK, DEX, and OAT binaries into human-readable source code using a native implementation that does not require a Java Virtual Machine. The platform is distinguished by its integration with Frida for dynamic analysis, allowing users to hook methods, inject custom JavaScript, and dump device memory in real time. It also features specialized security engines, including a taint propagation engine and a stack-state machine, to
Provides a mechanism to detect security flaws using user-defined expressions that match specific API calls, signatures, or configurations.
यह प्रोजेक्ट एक PyTorch मॉडल सर्विंग फ्रेमवर्क है जिसे स्केलेबल नेटवर्क एंडपॉइंट्स के माध्यम से प्रोडक्शन में मशीन लर्निंग मॉडल को तैनात और स्केल करने के लिए डिज़ाइन किया गया है। यह एक उच्च-प्रदर्शन इन्फरेंस सर्वर, ऑप्टिमाइज़र और मॉडल लाइफसाइकिल मैनेजर के रूप में कार्य करता है जो मॉडल लोडिंग, रिक्वेस्ट बैचिंग और हार्डवेयर एक्सेलेरेशन को संभालता है। यह सिस्टम उन्नत ऑर्केस्ट्रेशन और ऑप्टिमाइज़ेशन क्षमताओं के माध्यम से खुद को अलग करता है, जैसे कि निष्पादन ग्राफ़ का उपयोग करके कई मॉडलों को अनुक्रमिक वर्कफ़्लो में जोड़ना और थ्रूपुट व विलंबता में सुधार करने के लिए डायनेमिक बैचिंग को नियोजित करना। यह निरंतर बैचिंग और टेंसर समानता (tensor parallelism) के माध्यम से जेनरेटिव AI और बड़े भाषा मॉडल के लिए विशेष समर्थन प्रदान करता है। व्यापक क्षमता क्षेत्रों में NVIDIA, AMD और Apple Silicon जैसे विविध हार्डवेयर पर GPU संसाधन प्रबंधन, साथ ही पंजीकरण, संस्करण और वर्कर स्केलिंग के लिए व्यापक मॉडल लाइफसाइकिल प्रबंधन शामिल है। यह Prometheus-संगत मेट्रिक्स के माध्यम से सिस्टम स्वास्थ्य और मॉडल प्रदर्शन को ट्रैक करने के लिए ऑब्जर्वेबिलिटी टूल्स को भी एकीकृत करता है। सर्वर को लाइफसाइकिल नियंत्रण और रनटाइम मापदंडों के कॉन्फ़िगरेशन के लिए उपयोग किए जाने वाले कमांड-लाइन इंटरफ़ेस के माध्यम से प्रबंधित किया जाता है।
Integrates custom plugins to perform runtime security scanning on model files during loading.
Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource
Offers a pluggable architecture for defining custom security tests and API probes.
LLM Guard is a security firewall and guardrail framework designed to scan and sanitize inputs and outputs for large language models. It functions as a proxy gateway and security layer to block prompt injections, toxicity, and sensitive data leakage while ensuring that model interactions remain compliant with organizational policies. The system distinguishes itself through a modular scanner pipeline that utilizes local model orchestration to eliminate external network dependencies. It supports real-time security filtering via streaming chunk analysis and implements a fail-fast execution model
Provides a pluggable architecture for defining custom scanning methods to identify specific security risks.