19 रिपॉजिटरी
Utilities for narrowing the scope of security scans by including or excluding specific rules.
Distinguishing note: Focuses on the runtime selection of detection rules during a scan operation.
Explore 19 awesome GitHub repositories matching security & cryptography · Scan Filtering Tools. Refine with filters or upvote what's useful.
Trufflehog is a security tool designed to continuously monitor code repositories and cloud environments to detect, verify, and remediate exposed sensitive credentials and API keys. It functions as a comprehensive secret scanning engine that integrates directly into deployment pipelines and version control systems to intercept sensitive data before it is committed or pushed. By utilizing read-only operations and volatile memory processing, the system ensures that discovered credentials are never stored persistently, maintaining strict data privacy throughout the scanning lifecycle. The platfor
Includes or excludes specific detection rules by providing a list of identifiers during a scan operation.
dirsearch is a command-line security tool and web path scanner used for discovering hidden directories and files on web servers. It functions as a recursive directory fuzzer and brute-force utility that identifies undocumented paths and sensitive files using wordlists and HTTP status codes. The tool distinguishes itself through template-driven path generation and an automated HTTP response filter that uses status codes, content length, and regex patterns to isolate valid targets. It supports recursive directory crawling to map complex web structures and provides state-persistence serializatio
Targets a predefined list of known sub-directories to search for hidden content within specific paths.
Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc
Filters infrastructure assets to prioritize critical systems during security scans.
This project is a command-line synchronization client for OneDrive and SharePoint libraries on Linux. It functions as a synchronization engine that aligns local filesystems with cloud storage through bidirectional, unidirectional, or download-only workflows. The client supports headless authentication for servers without web browsers and can be deployed as a background service or within a containerized environment. It enables the management of multiple distinct cloud accounts on a single system and integrates with shared SharePoint sites and document libraries. The synchronization engine inc
Excludes specific files or directories from the synchronization process using wildcard rules and inclusion lists.
Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security
Controls which policies execute during a run by including or excluding specific check IDs or severity levels.
AndResGuard is a utility for Android asset optimization, resource shrinking, and resource obfuscation. Its primary purpose is to minimize the final application package footprint by compressing resource files, removing unnecessary data, and optimizing the resource table. The project focuses on preventing reverse engineering by renaming resource types and file names to short, randomized identifiers. It includes mechanisms to preserve specific assets through the use of whitelists and wildcard-driven exclusion patterns, ensuring compatibility with dynamic lookup requirements. Additional capabili
Uses pattern matching to automatically protect groups of resources from the obfuscation process.
reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio
Provides rules to omit specific network assets or infrastructure from security scan operations to maintain authorized boundaries.
WhatWeb is a web application fingerprinting tool that identifies the technology stack powering a website by scanning HTTP responses and page content. It matches responses against a library of over 1800 signatures to detect CMS platforms, JavaScript libraries, web servers, embedded devices, and third-party addons, while also extracting technical metadata such as software versions, user accounts, and module names. The tool operates through a plugin-based detection framework that supports both passive and aggressive scanning modes. Passive plugins analyze existing HTTP headers and page content w
Limits scan results to targets matching custom text strings, regular expressions, or specific plugins.
AutoRecon is an automated network reconnaissance tool that performs concurrent port scanning and service enumeration across multiple targets. It operates as a multi-target port scanner, probing IP addresses, CIDR ranges, or hostnames in parallel, and automatically dispatches service-specific enumeration tools after port detection to gather detailed information about each open service. The tool distinguishes itself through a plugin-based scanning system that allows extending or replacing default port and service scans via a flexible plugin architecture. It provides real-time pattern-based outp
Highlights and extracts matching lines from command output using global or per-scan patterns.
Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet
Matches multiple targets with prefix, suffix, or multiple asterisk wildcards in a single exclusion pattern.
ToolGood.Words एक संवेदनशील शब्द फ़िल्टरिंग लाइब्रेरी और टेक्स्ट सैनिटाइज़ेशन घटक है जिसे निषिद्ध शब्दों का पता लगाने और उन्हें मास्क करने के लिए डिज़ाइन किया गया है। यह चीनी टेक्स्ट सामान्यीकरण, पिनयिन लिप्यंतरण और प्रतिबंधित शब्दों को प्लेसहोल्डर के साथ बदलने के लिए टूल प्रदान करता है। यह प्रोजेक्ट पिनयिन लिप्यंतरण इंजन और ध्वन्यात्मक-आधारित पहचान के माध्यम से अस्पष्ट भाषा को उजागर करने की अपनी क्षमता से अलग है। यह ध्वन्यात्मक प्रतिस्थापन, पहले अक्षर के शुरुआती अक्षरों, या जानबूझकर की गई वर्तनी की गलतियों द्वारा छिपी हुई संवेदनशील सामग्री की पहचान करता है। यह लाइब्रेरी टेक्स्ट प्रोसेसिंग क्षमताओं की एक विस्तृत श्रृंखला को कवर करती है, जिसमें सरलीकृत और पारंपरिक चीनी के बीच वर्ण सेट रूपांतरण, पूर्ण-चौड़ाई और आधी-चौड़ाई वर्ण स्वरूपण, और वाइल्डकार्ड पैटर्न मिलान शामिल है। ये उपयोगिताएँ एक सामान्यीकरण वर्कफ़्लो का समर्थन करती हैं जो फ़िल्टरिंग और मास्किंग लॉजिक लागू करने से पहले इनपुट को मानकीकृत करती है।
Detects sensitive words using regular expression patterns and wildcards to match various forms of a term.
Reflections एक Java क्लासपाथ स्कैनिंग लाइब्रेरी और मेटाडेटा इंडेक्सर है जिसे रनटाइम पर क्लासेस, मेथड्स और रिसोर्सेज का पता लगाने के लिए डिज़ाइन किया गया है। यह एनोटेशन डिस्कवरी और टाइप पदानुक्रम विश्लेषण के लिए एक टूल के रूप में कार्य करता है, जो सिस्टम को विशिष्ट एनोटेशन के साथ चिह्नित तत्वों की पहचान करने या Java वर्चुअल मशीन के भीतर सुपर-टाइप्स और सबटाइप्स को हल करने की अनुमति देता है। यह प्रोजेक्ट मेटाडेटा सीरियलाइज़ेशन के माध्यम से खुद को अलग करता है, जो स्कैन किए गए इंडेक्स को पर्सिस्टेंट फ़ाइलों या सोर्स कोड में सहेजने के लिए तंत्र प्रदान करता है। यह क्षमता बार-बार, महंगे क्लासपाथ स्कैन की आवश्यकता को समाप्त करके एप्लिकेशन स्टार्टअप ओवरहेड को कम करती है। लाइब्रेरी हस्ताक्षर और एक्सेस मॉडिफायर्स के आधार पर क्लास मेंबर्स की इंडेक्सिंग, नॉन-बाइटकोड रिसोर्स फ़ाइलों की खोज, और टाइप सिस्टम मेटाडेटा को फ़िल्टर और ट्रांसफ़ॉर्म करने के लिए फंक्शनल क्वेरी कंपोज़िशन के उपयोग सहित व्यापक क्षमता क्षेत्रों को कवर करती है। यह बेहतर परफॉरमेंस के लिए स्कैन सीमाओं और समावेशन पैटर्न को परिभाषित करने के लिए कॉन्फ़िगरेशन यूटिलिटीज भी प्रदान करती है।
Applies predicates to resource names to exclude specific non-class files from the scanning process.
Ziggy is a frontend route bridge and JavaScript route resolver that allows Laravel route names and parameters to be used within JavaScript and TypeScript environments. It serves as a synchronization layer that exports backend route configurations to frontend assets, ensuring that frontend navigation remains in sync with backend route definitions. The project provides a TypeScript route type generator that produces strict type definitions for route names and parameters to enable IDE autocompletion. It includes a route exposure filtering system that uses inclusion and exclusion patterns to cont
Restricts exported route lists using inclusion and exclusion patterns to prevent sensitive endpoints from leaking to clients.
Ziggy is a frontend routing bridge that exports server route definitions to JavaScript or JSON for use in browser-based applications. It acts as a named route resolver, synchronizing server-defined routes with the client to generate full URLs from named routes without hardcoding paths. The project includes a TypeScript route generator that creates type definitions for backend routes, providing static type checking and autocompletion. It also provides dedicated integration hooks and plugins for React and Vue to make routing capabilities available within component-based frameworks. Beyond URL
Limits the exported route manifest using inclusion or exclusion lists to reduce the payload sent to the browser.
afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points. The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify
Includes utilities for narrowing the scope of security scans by filtering targets based on keywords or severity.
यह प्रोजेक्ट एक VS Code सेटिंग्स सिंक्रोनाइज़र और डेवलपर एनवायरनमेंट मैनेजर है जिसे कई मशीनों पर सुसंगत एडिटर कॉन्फ़िगरेशन, कीबाइंडिंग और एक्सटेंशन सूचियों को बनाए रखने के लिए डिज़ाइन किया गया है। यह एक कॉन्फ़िगरेशन बैकअप टूल के रूप में कार्य करता है जो सेटअप फाइलों को होस्ट और वितरित करने के लिए रिमोट स्टोरेज बैकएंड के रूप में GitHub Gists का उपयोग करता है। यह सिस्टम विभिन्न ऑपरेटिंग सिस्टम और हार्डवेयर पर प्लगइन सेट और मुख्य सेटिंग्स को मिरर करके डेवलपर एनवायरनमेंट पोर्टेबिलिटी को सक्षम बनाता है। यह एब्सोल्यूट पाथ फाइल मैपिंग के माध्यम से कस्टम कोड स्निपेट्स और नॉन-स्टैंडर्ड कॉन्फ़िगरेशन फाइलों के सिंक्रोनाइज़ेशन का समर्थन करता है। टूल में डेटा बहिष्करण और स्थानीय सेटिंग्स संरक्षण को नियंत्रित करने के लिए एक सिंक्रोनाइज़ेशन प्रबंधन इंटरफेस शामिल है, जो मशीन-विशिष्ट ओवरराइड्स को ओवरराइट होने से रोकता है। यह एनवायरनमेंट-आधारित सेटिंग्स फिल्टरिंग और GitHub Enterprise API एकीकरण के माध्यम से निजी कॉर्पोरेट नेटवर्क से जुड़ने की क्षमता प्रदान करता है। डेटा सिंक्रोनाइज़ेशन को मैन्युअल अपलोड और इवेंट-संचालित ट्रिगर्स दोनों के माध्यम से संभाला जाता है जो स्थानीय फाइल संशोधनों या एप्लिकेशन स्टार्टअप पर अपडेट शुरू करते हैं।
Prevents designated files or folders from being uploaded to the remote store to protect sensitive information.
Typos is a source code spell checker and automated typo fixer designed to detect and correct spelling errors across programming languages and project files. It functions as a CI spelling validator and SARIF compatible linter, allowing projects to prevent misspelled text from reaching production. The tool features a customizable dictionary engine that utilizes TOML configuration and locale-specific dictionaries to manage project-specific terminology. It differentiates itself by splitting programming language identifiers into individual words for validation and verifying the spelling of filenam
Filters out technical noise like UUIDs, SHAs, and JWT tokens to reduce false positive spell-check alerts.
This utility is a command-line tool designed to create incremental, time-stamped snapshots of local or remote data. It functions as a shell-based orchestrator that coordinates system utilities to maintain versioned file archives, allowing for the restoration of specific data states without the need for proprietary software. The tool distinguishes itself by using filesystem hard links to reference unchanged files across multiple snapshots, which minimizes storage consumption while keeping each backup directory structure independent. It incorporates a dedicated retention manager that automatica
Filters file paths against user-defined rules to selectively include or omit data from the synchronization process.
Laravel migrations generator is a database tool that inspects existing relational schemas and automatically generates framework migration files to reverse engineer databases. It connects directly to relational database system catalogs to read existing tables, columns, indexes, and constraints, sorting table creation and constraint generation into separate sequences to satisfy relational dependency requirements. The tool communicates with multiple database engine dialects through a unified schema inspection interface and evaluates whitelist and blacklist patterns during metadata collection to
Evaluates whitelist and blacklist patterns during metadata collection to omit unwanted tables, views, and vendor data.